Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-0899

Опубликовано: 31 авг. 2017
Источник: debian
EPSS Низкий

Описание

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby2.3fixed2.3.3-1+deb9u1package
ruby2.1removedpackage
ruby1.9.1removedpackage
rubygemsfixed3.2.0~rc.1-1package

Примечания

  • https://www.ruby-lang.org/en/news/2017/08/29/multiple-vulnerabilities-in-rubygems/

  • http://blog.rubygems.org/2017/08/27/2.6.13-released.html

  • For Ruby 2.3.4: https://bugs.ruby-lang.org/attachments/download/6691/rubygems-2613-ruby23.patch

  • For Ruby 2.2.7: https://bugs.ruby-lang.org/attachments/download/6690/rubygems-2613-ruby22.patch

  • Not considered a vulnerability per se, if this affects a terminal emulator it's a bug there

EPSS

Процентиль: 93%
0.09672
Низкий

Связанные уязвимости

CVSS3: 9.8
ubuntu
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

CVSS3: 4.3
redhat
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

CVSS3: 9.8
nvd
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

CVSS3: 9.8
github
больше 3 лет назад

RubyGems Code Injection vulnerability

oracle-oval
больше 7 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS

Процентиль: 93%
0.09672
Низкий