CVE-2013-0334: Input Validation
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0334?
CVE-2013-0334 is considered a moderate severity vulnerability due to its potential for unauthorized gem installation.
How do I fix CVE-2013-0334?
To fix CVE-2013-0334, upgrade Bundler to version 1.7 or later where the vulnerability is addressed.
Which software is affected by CVE-2013-0334?
CVE-2013-0334 affects versions of Bundler prior to 1.7 and also impacts specific versions of openSUSE and Fedora operating systems.
Can CVE-2013-0334 allow installation of malicious gems?
Yes, CVE-2013-0334 can allow remote attackers to install malicious gems by exploiting the vulnerability with gem name conflicts.
What is the impact of exploiting CVE-2013-0334?
Exploiting CVE-2013-0334 can lead to the execution of malicious code in applications that rely on Bundler for dependency management.