PT-2007-1934 · Ruby · Rubygems

Published

2007-01-24

·

Updated

2026-05-04

·

CVE-2007-0469

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions RubyGems versions prior to 0.9.1
Description The issue concerns the extract files function in installer.rb, which does not check whether files exist before overwriting them. This allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.
Recommendations For RubyGems versions prior to 0.9.1, update to version 0.9.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the extract files function in installer.rb to minimize the risk of exploitation. Avoid using crafted GEM packages until the issue is resolved.

Fix

Related Identifiers

CVE-2007-0469
GHSA-95VX-Q4C2-64GR

Affected Products

Rubygems