REDHAT-BUG-1692520: High severity rubygems vulnerability
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensureloadablespec during the preinstall check.
Upstream patch:
https://bugs.ruby-lang.org/attachments/7669
References:
https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/ https://blog.rubygems.org/2019/03/05/security-advisories-2019-03.html
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1692520?
The severity of REDHAT-BUG-1692520 is considered critical due to the potential for arbitrary code execution.
How do I fix REDHAT-BUG-1692520?
To fix REDHAT-BUG-1692520, upgrade RubyGems to a version higher than 3.0.2, where the vulnerability has been patched.
Which versions of RubyGems are affected by REDHAT-BUG-1692520?
RubyGems versions from 2.6 to 3.0.2 are affected by the vulnerability defined in REDHAT-BUG-1692520.
Can REDHAT-BUG-1692520 be exploited remotely?
Yes, REDHAT-BUG-1692520 can potentially be exploited remotely through the installation of a malicious gem.
What are the consequences of an exploit for REDHAT-BUG-1692520?
Exploiting REDHAT-BUG-1692520 allows an attacker to execute arbitrary code on the victim's system, leading to potential data breaches and system compromise.