CVE-2018-1000079
Summary
| CVE | CVE-2018-1000079 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-13 15:29:00 UTC |
| Updated | 2018-11-30 11:29:00 UTC |
| Description | RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| 2.7.6 Released - RubyGems Blog | MISC | blog.rubygems.org | Vendor Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Debian -- Security Information -- DSA-4219-1 jruby | DEBIAN | www.debian.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Implement a safe mkdir for package that verifies were inside the dest… · rubygems/rubygems@666ef79 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| [SECURITY] [DLA 1421-1] ruby2.1 security update | MLIST | lists.debian.org | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Add bug fix for #270068 · rubygems/rubygems@f83f911 · GitHub | MISC | github.com | Patch, Third Party Advisory |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| USN-3621-1: Ruby vulnerabilities | Ubuntu security notices | UBUNTU | usn.ubuntu.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| Red Hat Customer Portal | REDHAT | access.redhat.com | |
| [security-announce] openSUSE-SU-2019:1771-1: important: Security update | SUSE | lists.opensuse.org | |
| Debian -- Security Information -- DSA-4259-1 ruby2.3 | DEBIAN | www.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 377477 Alibaba Cloud Linux Security Update for ruby (ALINUX2-SA-2019:0111)