UBUNTU-CVE-2019-8325
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-8325
UBUNTU-CVE-2019-8325
Summary:
Details: An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.)
References: https://ubuntu.com/security/CVE-2019-8325, https://bugs.ruby-lang.org/attachments/7669, https://bugs.ruby-lang.org/attachments/7670, https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/, https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html, https://ubuntu.com/security/notices/USN-3945-1, https://www.cve.org/CVERecord?id=CVE-2019-8325
Affected packages
Package
Name: ruby1.9.1
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
