cbcvebase.
CVE-2017-0900
published 2017-08-31

CVE-2017-0900: RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who…

high7.5CVSS 3.0
AVNACLPRNUINSUCNINAH
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

Affected

18 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianrubygems< rubygems 3.2.0~rc.1-1 (bookworm)rubygems 3.2.0~rc.1-1 (bookworm)
redhatenterprise_linux_desktop
redhatenterprise_linux_server
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_aus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_eus
redhatenterprise_linux_server_tus
redhatenterprise_linux_server_tus
redhatenterprise_linux_workstation
rubygemsrubygems<= 2.6.12
rubygemsrubygems>= 0 < 3.2.0~rc.1-13.2.0~rc.1-1
rubygemsrubygems>= 0 < 3.2.0~rc.1-13.2.0~rc.1-1
rubygemsrubygems>= 0 < 3.2.0~rc.1-13.2.0~rc.1-1
rubygemsrubygems>= 0 < 3.2.0~rc.1-13.2.0~rc.1-1

CVSS provenance

nvdv3.07.5HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv9.1CRITICAL