[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247621

 
 

909

 
 

194512

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2015:2180-07 -- Redhat rubygem-bundler, rubygem-thor

ID: oval:org.secpod.oval:def:501684Date: (C)2015-11-25   (M)2022-09-09
Class: PATCHFamily: unix




Bundler manages an application"s dependencies through its entire life, across many machines, systematically and repeatably. Thor is a toolkit for building powerful command-line interfaces. A flaw was found in the way Bundler handled gems available from multiple sources. An attacker with access to one of the sources could create a malicious gem with the same name, which they could then use to trick a user into installing, potentially resulting in execution of code from the attacker-supplied malicious gem. Bundler has been upgraded to upstream version 1.7.8 and Thor has been upgraded to upstream version 1.19.1, both of which provide a number of bug fixes and enhancements over the previous versions. All rubygem-bundler and rubygem-thor users are advised to upgrade to these updated packages, which correct these issues and add these enhancements.

Platform:
Red Hat Enterprise Linux 7
Product:
rubygem-bundler
rubygem-thor
Reference:
RHSA-2015:2180-07
CVE-2013-0334
CVE    1
CVE-2013-0334
CPE    3
cpe:/a:rubygems.org:rubygem-thor
cpe:/o:redhat:enterprise_linux:7
cpe:/a:gembundler:rubygem-bundler

© SecPod Technologies