Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Debian 7 Wheezy DLA-1112-1 Moderate: Rubygems DoS and File Overwrite

debian lts
Calendar Grey September 27, 2017
Dist Debian Esm H88
Upgrade Rubygems on Debian 7 Wheezy to improve security against DOS and file overwrite vulnerabilities with easy steps to follow for effective results
Some vulnerabilities were found in the Rubygems package that affects the LTS distribution

Summary

CVE-2017-0900

DOS vulernerability in the query command

CVE-2017-0901

gem installer allows a malicious gem to overwrite arbitrary files

For Debian 7 "Wheezy", these problems have been fixed in version
1.8.24-1+deb7u1.

We recommend that you upgrade your rubygems packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS


Package: rubygems
Version: 1.8.24-1+deb7u1
CVE ID: CVE-2017-0900 CVE-2017-0901
Debian Bug: 873802

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here