CVE-2017-0899: Code Injection
Last updated 24 July 2024
Other sources
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
Upstream patches:
https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1 https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491
Bug report:
https://hackerone.com/reports/226335
External References:
http://blog.rubygems.org/2017/08/27/2.6.13-released.html
— Red Hat
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2017-0899?
CVE-2017-0899 refers to a vulnerability in RubyGems version 2.6.12 and earlier that allows maliciously crafted gem specifications to execute terminal escape sequences.
How severe is the vulnerability CVE-2017-0899?
The severity of vulnerability CVE-2017-0899 is critical with a severity score of 9.8.
Which software versions are affected by CVE-2017-0899?
RubyGems version 2.6.12 and earlier are affected by CVE-2017-0899.
How can I fix the vulnerability CVE-2017-0899?
To fix the vulnerability CVE-2017-0899, update RubyGems to version 2.6.13 or later.
Where can I find more information about CVE-2017-0899?
You can find more information about CVE-2017-0899 in the references provided: [http://blog.rubygems.org/2017/08/27/2.6.13-released.html](http://blog.rubygems.org/2017/08/27/2.6.13-released.html), [https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1](https://github.com/rubygems/rubygems/commit/1bcbc7fe637b03145401ec9c094066285934a7f1), [https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491](https://github.com/rubygems/rubygems/commit/ef0aa611effb5f54d40c7fba6e8235eb43c5a491).