CVE-2018-1000074
published 2018-03-13CVE-2018-1000074: RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and…
PriorityP341high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.98%
85.8th percentile
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack appear to be exploitable via victim must run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability appears to have been fixed in 2.7.6.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | jruby | < jruby 9.1.17.0-1 (bookworm) | jruby 9.1.17.0-1 (bookworm) |
| debian | rubygems | < jruby 9.1.17.0-1 (bookworm) | jruby 9.1.17.0-1 (bookworm) |
| jruby | jruby | >= 0 < 9.1.17.0-1 | 9.1.17.0-1 |
| jruby | jruby | >= 0 < 9.1.17.0-1 | 9.1.17.0-1 |
| jruby | jruby | >= 0 < 9.1.17.0-1 | 9.1.17.0-1 |
| rubygems | rubygems | <= 2.2.9 | — |
| rubygems | rubygems | <= 2.3.6 | — |
| rubygems | rubygems | <= 2.4.3 | — |
| rubygems | rubygems | <= 2.5.0 | — |
| rubygems | rubygems | >= 0 < 3.2.0~rc.1-1 | 3.2.0~rc.1-1 |
| rubygems | rubygems | >= 0 < 3.2.0~rc.1-1 | 3.2.0~rc.1-1 |
| rubygems | rubygems | >= 0 < 3.2.0~rc.1-1 | 3.2.0~rc.1-1 |
| rubygems | rubygems | >= 0 < 3.2.0~rc.1-1 | 3.2.0~rc.1-1 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.1CRITICAL
vendor_ubuntu9.1CRITICAL
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
RubyGems Deserialization of Untrusted Data vulnerability
osv·2022-05-14
CVE-2018-1000074 [HIGH] RubyGems Deserialization of Untrusted Data vulnerability
RubyGems Deserialization of Untrusted Data vulnerability
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack requires the victim to run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability is fixed in 2.7.6.
GHSA
RubyGems Deserialization of Untrusted Data vulnerability
ghsa·2022-05-14
CVE-2018-1000074 [HIGH] CWE-502 RubyGems Deserialization of Untrusted Data vulnerability
RubyGems Deserialization of Untrusted Data vulnerability
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack requires the victim to run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability is fixed in 2.7.6.
OSV
ruby2.0 regression
osv·2021-03-25·CVSS 9.1
CVE-2017-0903 [CRITICAL] ruby2.0 regression
ruby2.0 regression
USN-3685-1 fixed a vulnerability in Ruby. The fix for CVE-2017-0903 introduced
a regression in Ruby. This update fixes the problem.
Original advisory details:
Some of these CVE were already addressed in previous
USN: 3439-1, 3553-1, 3528-1. Here we address for
the remain releases.
It was discovered that Ruby incorrectly handled certain inputs.
An attacker could use this to cause a buffer overrun. (CVE-2017-0898)
It was discovered that Ruby incorrectly handled certain files.
An attacker could use this to overwrite any file on the filesystem.
(CVE-2017-0901)
It was discovered that Ruby was vulnerable to a DNS hijacking vulnerability.
An attacker could use this to possibly force the RubyGems client to download
and install gems from a server that the attacker controls.
OSV
ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
osv·2018-06-13·CVSS 9.1
CVE-2017-0898 [CRITICAL] ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
Some of these CVE were already addressed in previous
USN: 3439-1, 3553-1, 3528-1. Here we address for
the remain releases.
It was discovered that Ruby incorrectly handled certain inputs.
An attacker could use this to cause a buffer overrun. (CVE-2017-0898)
It was discovered that Ruby incorrectly handled certain files.
An attacker could use this to overwrite any file on the filesystem.
(CVE-2017-0901)
It was discovered that Ruby was vulnerable to a DNS hijacking vulnerability.
An attacker could use this to possibly force the RubyGems client to download
and install gems from a server that the attacker controls. (CVE-2017-0902)
It was discovered that Ruby incorrectly handled certain YAML files.
An attacker could use this to possibly execute arb
OSV
ruby1.9.1, ruby2.0 regression
osv·2018-04-13·CVSS 7.5
CVE-2018-1000074 [HIGH] ruby1.9.1, ruby2.0 regression
ruby1.9.1, ruby2.0 regression
USN-3621-1 fixed vulnerabilities in Ruby. The update caused an issue due
to an incomplete patch for CVE-2018-1000074. This update reverts the
problematic patch pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ruby incorrectly handled certain inputs. An attacker
could possibly use this to access sensitive information. (CVE-2018-1000073)
It was discovered that Ruby incorrectly handled certain files. An attacker
could possibly use this to execute arbitrary code. (CVE-2018-1000074)
It was discovered that Ruby incorrectly handled certain files. An attacker
could possibly use this to cause a denial of service. (CVE-2018-1000075)
It was discovered that Ruby incorrectly handled certain crypto s
OSV
ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
osv·2018-04-05·CVSS 7.5
CVE-2018-1000073 [HIGH] ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
It was discovered that Ruby incorrectly handled certain inputs. An attacker
could possibly use this to access sensitive information. (CVE-2018-1000073)
It was discovered that Ruby incorrectly handled certain files. An attacker
could possibly use this to execute arbitrary code. (CVE-2018-1000074)
It was discovered that Ruby incorrectly handled certain files. An attacker
could possibly use this to cause a denial of service. (CVE-2018-1000075)
It was discovered that Ruby incorrectly handled certain crypto signatures.
An attacker could possibly use this to execute arbitrary code. (CVE-2018-1000076)
It was discovered that Ruby incorrectly handled certain inputs. An attacker
could possibly use this to execute arbitrary code. (CVE-2018-1000077,
CVE
OSV
CVE-2018-1000074: RubyGems version Ruby 2
osv·2018-03-13·CVSS 7.8
CVE-2018-1000074 [HIGH] CVE-2018-1000074: RubyGems version Ruby 2
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack appear to be exploitable via victim must run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability appears to have been fixed in 2.7.6.
Ubuntu
Ruby regression
vendor_ubuntu·2021-03-25·CVSS 9.1
CVE-2017-0903 [CRITICAL] Ruby regression
Title: Ruby regression
Summary: USN-3685-1 introduced a regression in Ruby.
USN-3685-1 fixed a vulnerability in Ruby. The fix for CVE-2017-0903 introduced
a regression in Ruby. This update fixes the problem.
Original advisory details:
Some of these CVE were already addressed in previous
USN: 3439-1, 3553-1, 3528-1. Here we address for
the remain releases.
It was discovered that Ruby incorrectly handled certain inputs.
An attacker could use this to cause a buffer overrun. (CVE-2017-0898)
It was discovered that Ruby incorrectly handled certain files.
An attacker could use this to overwrite any file on the filesystem.
(CVE-2017-0901)
It was discovered that Ruby was vulnerable to a DNS hijacking vulnerability.
An attacker could use this to possibly force the RubyGems client to download
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2018-06-13·CVSS 9.1
CVE-2017-0898 [CRITICAL] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
Some of these CVE were already addressed in previous
USN: 3439-1, 3553-1, 3528-1. Here we address for
the remain releases.
It was discovered that Ruby incorrectly handled certain inputs.
An attacker could use this to cause a buffer overrun. (CVE-2017-0898)
It was discovered that Ruby incorrectly handled certain files.
An attacker could use this to overwrite any file on the filesystem.
(CVE-2017-0901)
It was discovered that Ruby was vulnerable to a DNS hijacking vulnerability.
An attacker could use this to possibly force the RubyGems client to download
and install gems from a server that the attacker controls. (CVE-2017-0902)
It was discovered that Ruby incorrectly handled certain YAML files.
An attacker
Ubuntu
Ruby regression
vendor_ubuntu·2018-04-13·CVSS 7.5
CVE-2018-1000074 [HIGH] Ruby regression
Title: Ruby regression
Summary: USN-3621-1 caused a regression in Ruby.
USN-3621-1 fixed vulnerabilities in Ruby. The update caused an issue due
to an incomplete patch for CVE-2018-1000074. This update reverts the
problematic patch pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that Ruby incorrectly handled certain inputs. An attacker
could possibly use this to access sensitive information. (CVE-2018-1000073)
It was discovered that Ruby incorrectly handled certain files. An attacker
could possibly use this to execute arbitrary code. (CVE-2018-1000074)
It was discovered that Ruby incorrectly handled certain files. An attacker
could possibly use this to cause a denial of service. (CVE-2018-1000075)
It was discovered tha
Ubuntu
Ruby vulnerabilities
vendor_ubuntu·2018-04-05·CVSS 7.5
CVE-2018-1000073 [HIGH] Ruby vulnerabilities
Title: Ruby vulnerabilities
Summary: Several security issues were fixed in Ruby.
It was discovered that Ruby incorrectly handled certain inputs. An attacker
could possibly use this to access sensitive information. (CVE-2018-1000073)
It was discovered that Ruby incorrectly handled certain files. An attacker
could possibly use this to execute arbitrary code. (CVE-2018-1000074)
It was discovered that Ruby incorrectly handled certain files. An attacker
could possibly use this to cause a denial of service. (CVE-2018-1000075)
It was discovered that Ruby incorrectly handled certain crypto signatures.
An attacker could possibly use this to execute arbitrary code. (CVE-2018-1000076)
It was discovered that Ruby incorrectly handled certain inputs. An attacker
could possibly use this to execute
Red Hat
rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code execution on specially crafted YAML
vendor_redhat·2018-02-15·CVSS 7.8
CVE-2018-1000074 [HIGH] CWE-502 rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code execution on specially crafted YAML
rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code execution on specially crafted YAML
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack appear to be exploitable via victim must run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability appears to have been fixed in 2.7.6.
Statement: This issue affects the versions of rubygems as shipped with Red Hat Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having security impact of M
Debian
CVE-2018-1000074: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
vendor_debian·2018·CVSS 7.8
CVE-2018-1000074 [HIGH] CVE-2018-1000074: jruby - RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and ...
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a Deserialization of Untrusted Data vulnerability in owner command that can result in code execution. This attack appear to be exploitable via victim must run the `gem owner` command on a gem with a specially crafted YAML file. This vulnerability appears to have been fixed in 2.7.6.
Scope: local
bookworm: resolved (fixed in 9.1.17.0-1)
forky: resolved (fixed in 9.1.17.0-1)
sid: resolved (fixed in 9.1.17.0-1)
trixie: resolved (fixed in 9.1.17.0-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2018-1000074 rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code execution on specially crafted YAML
bugzilla·2018-02-21·CVSS 7.8
CVE-2018-1000074 [HIGH] CVE-2018-1000074 rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code execution on specially crafted YAML
CVE-2018-1000074 rubygems: Unsafe Object Deserialization Vulnerability in gem owner allowing arbitrary code execution on specially crafted YAML
Unsafe object deserialization vulnerability in owner command was found allowing arbitrary code execution when gem owner is run on specially crafted YAML file.
Upstream fix:
https://github.com/rubygems/rubygems/commit/254e3d0ee873c008c0b74e8b8abcbdab4caa0a6d
External References:
https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/
Discussion:
Created rubygems tracking bugs for this issue:
Affects: fedora-all [bug 1547431]
---
Statement:
This issue affects the versions of rubygems as shipped with Red Hat Subscription Asset Manager 1.x. Red Hat Product Security has rated this issue as having security impact of
Bugzilla
CVE-2018-1000073 CVE-2018-1000074 CVE-2018-1000075 CVE-2018-1000076 CVE-2018-1000077 CVE-2018-1000078 CVE-2018-1000079 rubygems: various flaws [fedora-all]
bugzilla·2018-02-21·CVSS 7.5
CVE-2018-1000073 [HIGH] CVE-2018-1000073 CVE-2018-1000074 CVE-2018-1000075 CVE-2018-1000076 CVE-2018-1000077 CVE-2018-1000078 CVE-2018-1000079 rubygems: various flaws [fedora-all]
CVE-2018-1000073 CVE-2018-1000074 CVE-2018-1000075 CVE-2018-1000076 CVE-2018-1000077 CVE-2018-1000078 CVE-2018-1000079 rubygems: various flaws [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and th
http://blog.rubygems.org/2018/02/15/2.7.6-released.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.htmlhttps://access.redhat.com/errata/RHSA-2018:3729https://access.redhat.com/errata/RHSA-2018:3730https://access.redhat.com/errata/RHSA-2018:3731https://access.redhat.com/errata/RHSA-2019:2028https://access.redhat.com/errata/RHSA-2020:0542https://access.redhat.com/errata/RHSA-2020:0591https://access.redhat.com/errata/RHSA-2020:0663https://github.com/rubygems/rubygems/commit/254e3d0ee873c008c0b74e8b8abcbdab4caa0a6dhttps://lists.debian.org/debian-lts-announce/2018/04/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2018/08/msg00028.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00028.htmlhttps://usn.ubuntu.com/3621-1/https://usn.ubuntu.com/3621-2/https://usn.ubuntu.com/3685-1/https://www.debian.org/security/2018/dsa-4219https://www.debian.org/security/2018/dsa-4259http://blog.rubygems.org/2018/02/15/2.7.6-released.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.htmlhttps://access.redhat.com/errata/RHSA-2018:3729https://access.redhat.com/errata/RHSA-2018:3730https://access.redhat.com/errata/RHSA-2018:3731https://access.redhat.com/errata/RHSA-2019:2028https://access.redhat.com/errata/RHSA-2020:0542https://access.redhat.com/errata/RHSA-2020:0591https://access.redhat.com/errata/RHSA-2020:0663https://github.com/rubygems/rubygems/commit/254e3d0ee873c008c0b74e8b8abcbdab4caa0a6dhttps://lists.debian.org/debian-lts-announce/2018/04/msg00017.htmlhttps://lists.debian.org/debian-lts-announce/2018/08/msg00028.htmlhttps://lists.debian.org/debian-lts-announce/2019/05/msg00028.htmlhttps://usn.ubuntu.com/3621-1/https://usn.ubuntu.com/3621-2/https://usn.ubuntu.com/3685-1/https://www.debian.org/security/2018/dsa-4219https://www.debian.org/security/2018/dsa-4259
2018-03-13
Published