VDB

DEBIAN-CVE-2018-1000079

DEBIAN-CVE-2018-1000079 PUBLISHED CVSS 5.5 MEDIUM

RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Directory Traversal vulnerability in gem installation that can result in the gem could write to arbitrary filesystem locations during installation. This attack appear to be exploitable via the victim must install a malicious gem. This vulnerability appears to have been fixed in 2.7.6.

Risk Scores

CVSS v3.0
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Affected Products

VendorProductVersions
Debian:13rubygems0, 0, 0
Debian:13jruby0, 0, 0
Debian:12rubygems0, 0, 0
Debian:12jruby0, 0, 0
Debian:11rubygems0, 0, 0
Debian:14jruby0, 0, 0
Debian:14rubygems0, 0, 0

Timeline

  • Mar 13, 2018 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›