PT-2007-1934 · Ruby · Rubygems
Published
2007-01-24
·
Updated
2026-05-04
·
CVE-2007-0469
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
RubyGems versions prior to 0.9.1
Description
The issue concerns the
extract files function in installer.rb, which does not check whether files exist before overwriting them. This allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.Recommendations
For RubyGems versions prior to 0.9.1, update to version 0.9.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the
extract files function in installer.rb to minimize the risk of exploitation. Avoid using crafted GEM packages until the issue is resolved.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rubygems