CVE-2011-2686 describes a vulnerability in Ruby versions prior to 1.8.7-p352 where the random number generator's seed is not reset after a process forks. This flaw, a regression from Ruby 1.8.6 development, allows attackers to predict subsequent random numbers if they can observe the sequence in a different child process, impacting the ruby_lang product. With a CVSS score of 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N), it represents a medium-severity issue with low attack complexity and potential for information disclosure. There is no evidence of active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.8.7-334CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:*:*:*:*:*:*:*:* | ||
1.8.7CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.7:p22:*:*:*:*:*:* | ||
1.8.7CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.7:p71:*:*:*:*:*:* | ||
1.8.7CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.7:p72:*:*:*:*:*:* | ||
1.8.7-160CPE matchmatch criteria | cpe:2.3:a:ruby-lang:ruby:1.8.7-160:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.