UBUNTU-CVE-2018-1000079
Dashboard / Vulnerabilities / UBUNTU-CVE-2018-1000079
UBUNTU-CVE-2018-1000079
Summary:
Details: RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.
References: https://ubuntu.com/security/CVE-2018-1000079, https://github.com/rubygems/rubygems/commit/f83f911e19e27cbac1ccce7471d96642241dd759, https://github.com/rubygems/rubygems/commit/666ef793cad42eed96f7aee1cdf77865db921099, https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/, https://ubuntu.com/security/notices/USN-3621-1, https://www.cve.org/CVERecord?id=CVE-2018-1000079
Affected packages
Package
Name: ruby2.0
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
