ALAS-2015-548 --- ruby21 rubygem21 rubygems21ID: oval:org.secpod.oval:def:1200026 | Date: (C)2015-12-31 (M)2022-09-22 |
Class: PATCH | Family: unix |
RubyGems provides the ability of a domain to direct clients to a separate host that is used to fetch gems and make API calls against. This mechanism is implemented via DNS, specificly a SRV record _rubygems._tcp under the original requested domain. RubyGems did not validate the hostname returned in the SRV record before sending requests to it. As discussed upstream, CVE-2015-4020 is due to an incomplete fix for CVE-2015-3900 , which allowed redirection to an arbitrary gem server in any security domain.
Platform: |
Amazon Linux AMI |
Product: |
ruby21 |
rubygems21 |
rubygem21 |