[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

247085

 
 

909

 
 

194218

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2018-978 ---- ruby22 ruby23 ruby24 subpackages

ID: oval:org.secpod.oval:def:1600854Date: (C)2018-04-02   (M)2022-08-31
Class: PATCHFamily: unix




Unsafe object deserialization through YAML formatted gem specifications:A vulnerability was found where the rubygems module was vulnerable to an unsafe YAML deserialization when inspecting a gem. Applications inspecting gem files without installing them can be tricked to execute arbitrary code in the context of the ruby interpreter

Platform:
Amazon Linux AMI
Product:
ruby22
ruby23
ruby24
rubygems22
rubygems23
rubygems24
rubygem22
rubygem23
rubygem24
Reference:
ALAS-2018-978
CVE-2017-0903
CVE    1
CVE-2017-0903
CPE    10
cpe:/a:ruby:ruby23
cpe:/o:amazon:linux
cpe:/a:ruby:ruby22
cpe:/a:ruby:ruby24
...

© SecPod Technologies