UBUNTU-CVE-2019-8324
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-8324
UBUNTU-CVE-2019-8324
Summary:
Details: An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check.
References: https://ubuntu.com/security/CVE-2019-8324, https://bugs.ruby-lang.org/attachments/7669, https://bugs.ruby-lang.org/attachments/7670, https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/, https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html, https://ubuntu.com/security/notices/USN-3945-1, https://www.cve.org/CVERecord?id=CVE-2019-8324
Affected packages
Package
Name: ruby1.9.1
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
