UBUNTU-CVE-2019-8323
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-8323
UBUNTU-CVE-2019-8323
Summary:
Details: An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur.
References: https://ubuntu.com/security/CVE-2019-8323, https://bugs.ruby-lang.org/attachments/7669, https://bugs.ruby-lang.org/attachments/7670, https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/, https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html, https://ubuntu.com/security/notices/USN-3945-1, https://www.cve.org/CVERecord?id=CVE-2019-8323
Affected packages
Package
Name: ruby1.9.1
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
