Описание
Security update for rubygem-bundler
This update for rubygem-bundler fixes the following issue:
- CVE-2019-3881: Fixed insecure permissions on a directory in /tmp/ that allowed malicious code execution (bsc#1143436).
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.1
ruby2.5-rubygem-bundler-1.16.1-lp151.3.3.1
ruby2.5-rubygem-bundler-doc-1.16.1-lp151.3.3.1
Ссылки
- E-Mail link for openSUSE-SU-2020:0803-1
- SUSE Security Ratings
- SUSE Bug 1143436
- SUSE CVE CVE-2019-3881 page
Описание
Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.
Затронутые продукты
openSUSE Leap 15.1:ruby2.5-rubygem-bundler-1.16.1-lp151.3.3.1
openSUSE Leap 15.1:ruby2.5-rubygem-bundler-doc-1.16.1-lp151.3.3.1
Ссылки
- CVE-2019-3881
- SUSE Bug 1143436