VDB
ALPINE-CVE-2017-0899
ALPINE-CVE-2017-0899
PUBLISHED
CVSS 9.800000190734863 CRITICAL
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
Risk Scores
CVSS 3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alpine:v3.19 | ruby | 1.8.7, 0, 2.0.0 |
| Alpine:v3.6 | ruby | 0, 1.8.7_p160-r2, 1.8.7_p160-r3 |
| Alpine:v3.14 | ruby | 2.3.1-r1, 0, 2.4.1-r5 |
| Alpine:v3.22 | ruby | 0, 0, 0 |
| Alpine:v3.18 | ruby | 1.9.3_p327-r0, 1.9.3_p286-r1, 1.9.3_p286-r0 |
| Alpine:v3.21 | ruby | 0, 0, 0 |
| Alpine:v3.15 | ruby | 2.3.3-r2, 0, 1.8.7_p160-r2 |
| Alpine:v3.10 | ruby | 2.0.0_p247-r1, 2.0.0_p247-r0, 2.0.0_p195-r0 |
| Alpine:v3.3 | ruby | 1.8.7_p72-r2, 1.8.7_p160-r2, 1.8.7_p160-r3 |
| Alpine:v3.7 | ruby | 1.8.7_p174-r3, 0, 2.4.1-r5 |
| Alpine:v3.16 | ruby | 2.3.3-r0, 2.3.1-r1, 2.3.1-r0 |
| Alpine:v3.17 | ruby | 2.4.1-r2, 1.8.7_p72-r2, 2.3.1-r1 |
| Alpine:v3.20 | ruby | 0, 0, 0 |
| Alpine:v3.5 | ruby | 1.9.3_p385-r0, 0, 1.8.7_p160-r2 |
| Alpine:v3.12 | ruby | 0, 2.4.1-r4, 2.4.1-r5 |
| Alpine:v3.23 | ruby | 0, 0, 0 |
| Alpine:v3.4 | ruby | 2.2.2-r1, 1.8.7, 1.8.7 |
| Alpine:v3.9 | ruby | 2.0.0_p195-r0, 1.9.3_p194-r0, 1.8.7_p72-r2 |
| Alpine:v3.24 | ruby | 0 |
| Alpine:v3.11 | ruby | 2.0.0_p353-r1, 0, 1.8.7_p160-r2 |
…and 2 more
Timeline
- Aug 31, 2017 CVE Published
- Apr 30, 2026 Distribution Patch
- Jun 15, 2026 CVE Updated