Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2015-3900

Опубликовано: 24 июн. 2015
Источник: debian

Описание

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

Пакеты

ПакетСтатусВерсия исправленияРелизТип
rubygemsnot-affectedpackage
libgems-rubynot-affectedpackage
ruby1.8not-affectedpackage
ruby1.9.1not-affectedpackage
ruby2.1fixed2.1.5-4package
ruby2.1fixed2.1.5-2+deb8u2jessiepackage
ruby2.2fixed2.2.2-3package
jrubyfixed1.7.20.1-2package
jrubynot-affectedjessiepackage
jrubynot-affectedwheezypackage
jrubynot-affectedsqueezepackage

Примечания

  • https://github.com/rubygems/rubygems/commit/6bbee35

  • https://github.com/rubygems/rubygems/commit/5c7bfb5

  • http://blog.rubygems.org/2015/05/14/CVE-2015-3900.html

Связанные уязвимости

ubuntu
больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

redhat
больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

nvd
больше 10 лет назад

RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."

github
больше 3 лет назад

RubyGems vulnerable to DNS hijack attack

suse-cvrf
почти 9 лет назад

Security update for ruby2.1