cbcvebase.
CVE-2017-0899
published 2017-08-31

CVE-2017-0899: RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem…

critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.

Affected

19 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianrubygems< rubygems 3.2.0~rc.1-1 (bookworm)rubygems 3.2.0~rc.1-1 (bookworm)
hackeronerubygems
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
rubygemsrubygems<= 2.6.12
rubygemsrubygems>= 0 < 3.2.0~rc.1-13.2.0~rc.1-1
rubygemsrubygems>= 0 < 3.2.0~rc.1-13.2.0~rc.1-1
rubygemsrubygems>= 0 < 3.2.0~rc.1-13.2.0~rc.1-1
rubygemsrubygems>= 0 < 3.2.0~rc.1-13.2.0~rc.1-1

CVSS provenance

nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL