CVE-2013-2065: Opensuse

Medium severity, CVSS 6.4. EPSS: 2.5% chance of exploitation in the next 30 days.

(1) DL and (2) Fiddle in Ruby 1.9 before 1.9.3 patchlevel 426, and 2.0 before 2.0.0 patchlevel 195, do not perform taint checking for native functions, which allows context-dependent attackers to bypass intended $SAFE level restrictions.

Affected products

  • Opensuse Opensuse: version 12.2 only; version 12.3 only
  • Ruby-Lang Ruby: version 1.9 only; version 1.9.1 only; version 1.9.2 only; version 1.9.3 only; version 2.0 only; version 2.0.0 only

Published 2013-11-02. Last modified 2026-06-16.