First published: Fri Oct 31 2014(Updated: )
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Bundler | <1.7.0 | |
SUSE Linux | =13.1 | |
SUSE Linux | =13.2 | |
Fedora | =19 | |
Fedora | =20 | |
Fedora | =21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0334 is considered a moderate severity vulnerability due to its potential for unauthorized gem installation.
To fix CVE-2013-0334, upgrade Bundler to version 1.7 or later where the vulnerability is addressed.
CVE-2013-0334 affects versions of Bundler prior to 1.7 and also impacts specific versions of openSUSE and Fedora operating systems.
Yes, CVE-2013-0334 can allow remote attackers to install malicious gems by exploiting the vulnerability with gem name conflicts.
Exploiting CVE-2013-0334 can lead to the execution of malicious code in applications that rely on Bundler for dependency management.