---
cve: "CVE-2009-5147"
severity: "LOW"
cvss: 3.1
epss: "7.8%"
vendor: "n/a"
kev: false
exploited: false
published: "2017-03-29 14:59:00"
tags: [cve, security, low]
source: tsecurity.de CVE-Dossier
exported: "2026-09-08T03:19:52+02:00"
---

# CVE-2009-5147

> 3.1 LOW · 🧪 PoC

## Beschreibung

DL::dlopen in Ruby 1.8, 1.9.0, 1.9.2, 1.9.3, 2.0.0 before patchlevel 648, and 2.1 before 2.1.8 opens libraries with tainted names.

## Referenzen

- <https://github.com/ruby/ruby/commit/4600cf725a86ce31266153647ae5aa1197b1215b>
- <http://seclists.org/oss-sec/2015/q3/222>
- <https://www.ruby-lang.org/en/news/2015/12/16/unsafe-tainted-string-usage-in-fiddle-and-dl-cve-2015-7551/>
- <https://access.redhat.com/errata/RHSA-2018:0583>
- <https://bugzilla.redhat.com/show_bug.cgi?id=1248935>
- <http://www.securityfocus.com/bid/76060>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2009-5147) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
