Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-0902

Опубликовано: 31 авг. 2017
Источник: debian
EPSS Низкий

Описание

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
ruby2.3fixed2.3.3-1+deb9u1package
ruby2.1removedpackage
ruby1.9.1removedpackage
ruby1.9.1not-affectedwheezypackage
rubygemsfixed3.2.0~rc.1-1package
rubygemsnot-affectedwheezypackage

Примечания

  • https://www.ruby-lang.org/en/news/2017/08/29/multiple-vulnerabilities-in-rubygems/

  • http://blog.rubygems.org/2017/08/27/2.6.13-released.html

  • For Ruby 2.3.4: https://bugs.ruby-lang.org/attachments/download/6691/rubygems-2613-ruby23.patch

  • For Ruby 2.2.7: https://bugs.ruby-lang.org/attachments/download/6690/rubygems-2613-ruby22.patch

EPSS

Процентиль: 87%
0.03392
Низкий

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

CVSS3: 7.5
redhat
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

CVSS3: 8.1
nvd
около 8 лет назад

RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking vulnerability that allows a MITM attacker to force the RubyGems client to download and install gems from a server that the attacker controls.

CVSS3: 8.1
github
больше 3 лет назад

RubyGems has Origin Validation Error vulnerability

oracle-oval
больше 7 лет назад

ELSA-2018-0378: ruby security update (IMPORTANT)

EPSS

Процентиль: 87%
0.03392
Низкий