CVE-2017-0900Improper Input Validation in Rubygems

Severity
7.5HIGHNVD
OSV9.1
EPSS
11.2%
top 6.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 31
Latest updateMay 14

Description

RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications to cause a denial of service attack against RubyGems clients who have issued a `query` command.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Also affects: Debian Linux 8.0, 9.0, Enterprise Linux 7.4, 7.6, 7.5

Patches

🔴Vulnerability Details

5
GHSA
RubyGems Improper Input Validation vulnerability2022-05-14
OSV
RubyGems Improper Input Validation vulnerability2022-05-14
OSV
ruby1.9.1 vulnerabilities2017-10-05
OSV
CVE-2017-0900: RubyGems version 22017-08-31
CVEList
CVE-2017-0900: RubyGems version 22017-08-31

📋Vendor Advisories

3
Ubuntu
Ruby vulnerabilities2017-10-05
Red Hat
rubygems: No size limit in summary length of gem spec2017-09-01
Debian
CVE-2017-0900: rubygems - RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem spe...2017

💬Community

2
Bugzilla
CVE-2017-0899 CVE-2017-0900 CVE-2017-0901 CVE-2017-0902 rubygems: various flaws [fedora-all]2017-09-01
Bugzilla
CVE-2017-0900 rubygems: No size limit in summary length of gem spec2017-09-01
CVE-2017-0900 — Improper Input Validation in Rubygems | cvebase