ZeroHour

CVE-2017-0901

PoC ×2
CVSS 3.0
7.5 high
EPSS
29%p98
Published
()
Modified
Description

RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.

Vendors
rubygemsdebiancanonicalredhat
Products
rubygems, debian linux, ubuntu linux, enterprise linux desktop, enterprise linux server, enterprise linux server aus, enterprise linux server eus, enterprise linux server tus, enterprise linux workstation
Weakness
CWE-22, CWE-20
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

In the news

No ingested article mentions this CVE yet.