Vulnerabilities > CVE-2007-0469 - Unspecified vulnerability in Rubyforge Rubygems 0.8.11
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN rubyforge
nessus
Summary
The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 2 |
Nessus
NASL family | SuSE Local Security Checks |
NASL id | SUSE_RUBYGEMS-2644.NASL |
description | This update fixes a vulnerability in rubygems that allowed to overwrite files with root privileges. (CVE-2007-0469) |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 27424 |
published | 2007-10-17 |
reporter | This script is Copyright (C) 2007-2019 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/27424 |
title | openSUSE 10 Security Update : rubygems (rubygems-2644) |
code |
|
References
- http://marc.info/?l=full-disclosure&m=116939816621060&w=2
- http://marc.info/?l=full-disclosure&m=116939816621060&w=2
- http://rubyforge.org/frs/shownotes.php?release_id=9074
- http://rubyforge.org/frs/shownotes.php?release_id=9074
- http://www.novell.com/linux/security/advisories/2007_4_sr.html
- http://www.novell.com/linux/security/advisories/2007_4_sr.html
- http://www.securityfocus.com/archive/1/458128/100/0/threaded
- http://www.securityfocus.com/archive/1/458128/100/0/threaded
- http://www.vupen.com/english/advisories/2007/0295
- http://www.vupen.com/english/advisories/2007/0295
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31688
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31688