UBUNTU-CVE-2019-3881
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-3881
UBUNTU-CVE-2019-3881
Summary:
Details: Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
References: https://ubuntu.com/security/CVE-2019-3881, https://salsa.debian.org/ruby-team/bundler/blob/debian/1.16.1-2/debian/patches/0006-Don-t-use-insecure-temporary-directory-as-home-direc.patch, https://salsa.debian.org/ruby-team/bundler/blob/debian/1.16.1-2/debian/patches/0007-Remove-temporary-home-directories.patch, https://ubuntu.com/security/notices/USN-4870-1, https://www.cve.org/CVERecord?id=CVE-2019-3881
Affected packages
Package
Name: bundler
Purl: pkg:deb/ubuntu/[email protected]~esm1?arch=source&distro=esm-apps/bionic
Affected ranges
Type: ECOSYSTEM
Events:
