VulnerabilityModified
CVE-2017-0899
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters.
CRITICAL 9.8EPSS 10.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 10.8%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 10.81% probability · 96th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-150, CWE-94
- Affected
- rubygems/rubygems · debian/debian linux · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- support@hackerone.com
References
- http://blog.rubygems.org/2017/08/27/2.6.13-released.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/100576Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039249Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3485Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0378Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0583Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0585Third Party Advisory
- https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1Patch, Third Party Advisory
- https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491Patch, Third Party Advisory
- https://hackerone.com/reports/226335Exploit, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201710-01Third Party Advisory
- https://www.debian.org/security/2017/dsa-3966Third Party Advisory
- http://blog.rubygems.org/2017/08/27/2.6.13-released.htmlPatch, Vendor Advisory
- http://www.securityfocus.com/bid/100576Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1039249Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:3485Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0378Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0583Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:0585Third Party Advisory
- https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1Patch, Third Party Advisory
- https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491Patch, Third Party Advisory
- https://hackerone.com/reports/226335Exploit, Patch, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlMailing List, Third Party Advisory
- https://security.gentoo.org/glsa/201710-01Third Party Advisory
- https://www.debian.org/security/2017/dsa-3966Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.