Sha256: 1bb7941a456e2311a187c2f3908c6cd361ddd5d5f828f8702468910754579dbf

Contents?: true

Size: 635 Bytes

Versions: 1

Compression:

Stored size: 635 Bytes

Contents

---
gem: rubygems-update
library: rubygems
cve: 2015-3900
osvdb: 122162
url: https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-007/?fid=6356
title: |
  RubyGems remote_fetcher.rb api_endpoint() Function Missing SRV Record
  Hostname Validation Request Hijacking
date: 2015-05-14
description: |
  RubyGems contains a flaw in the api_endpoint() function in remote_fetcher.rb
  that is triggered when handling hostnames in SRV records. With a specially
  crafted response, a context-dependent attacker may conduct DNS hijacking
  attacks.
cvss_v2: 5.0
patched_versions:
  - ~> 2.0.16
  - ~> 2.2.4
  - ">= 2.4.7"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/rubygems-update/CVE-2015-3900.yml