MGASA-2017-0482
Dashboard / Vulnerabilities / MGASA-2017-0482
MGASA-2017-0482
Summary: Updated ruby-RubyGems packages fix security vulnerabilities
Details: An ANSI escape sequence vulnerability (CVE-2017-0899). A DoS vulnerability in the query command (CVE-2017-0900). A vulnerability in the gem installer that allowed a malicious gem to overwrite arbitrary files (CVE-2017-0901). A DNS request hijacking vulnerability (CVE-2017-0902). An unsafe object deserialization vulnerability that allows an attacker to inject an instance of an object of their choosing in the target system. A clever attacker can inject an object that is able to interact with the system in such a way that will allow the attacker to execute arbitrary code (CVE-2017-0903).
References: https://advisories.mageia.org/MGASA-2017-0482.html, https://bugs.mageia.org/show_bug.cgi?id=21639, https://www.ruby-lang.org/en/news/2017/08/29/multiple-vulnerabilities-in-rubygems/, http://blog.rubygems.org/2017/10/09/unsafe-object-deserialization-vulnerability.html
Affected packages
Package
Name: ruby-RubyGems
Purl: pkg:rpm/mageia/ruby-RubyGems?arch=source&distro=mageia-5
Affected ranges
Type: ECOSYSTEM
Events:
