Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-0900

Опубликовано: 31 авг. 2017
Источник: debian
EPSS Низкий

Описание

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby2.3fixed2.3.3-1+deb9u1package
ruby2.1removedpackage
ruby1.9.1removedpackage
rubygemsfixed3.2.0~rc.1-1package

Примечания

  • https://www.ruby-lang.org/en/news/2017/08/29/multiple-vulnerabilities-in-rubygems/

  • http://blog.rubygems.org/2017/08/27/2.6.13-released.html

  • For Ruby 2.3.4: https://bugs.ruby-lang.org/attachments/download/6691/rubygems-2613-ruby23.patch

  • For Ruby 2.2.7: https://bugs.ruby-lang.org/attachments/download/6690/rubygems-2613-ruby22.patch

EPSS

Процентиль: 92%
0.09382
Низкий

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

CVSS3: 4.3
redhat
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

CVSS3: 7.5
nvd
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

CVSS3: 7.5
github
больше 3 лет назад

RubyGems Improper Input Validation vulnerability

oracle-oval
больше 7 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS

Процентиль: 92%
0.09382
Низкий