Sha256: 1bb7941a456e2311a187c2f3908c6cd361ddd5d5f828f8702468910754579dbf
Contents?: true
Size: 635 Bytes
Versions: 1
Compression:
Stored size: 635 Bytes
Contents
--- gem: rubygems-update library: rubygems cve: 2015-3900 osvdb: 122162 url: https://www.trustwave.com/Resources/Security-Advisories/Advisories/TWSL2015-007/?fid=6356 title: | RubyGems remote_fetcher.rb api_endpoint() Function Missing SRV Record Hostname Validation Request Hijacking date: 2015-05-14 description: | RubyGems contains a flaw in the api_endpoint() function in remote_fetcher.rb that is triggered when handling hostnames in SRV records. With a specially crafted response, a context-dependent attacker may conduct DNS hijacking attacks. cvss_v2: 5.0 patched_versions: - ~> 2.0.16 - ~> 2.2.4 - ">= 2.4.7"
Version data entries
1 entries across 1 versions & 1 rubygems
Version | Path |
---|---|
bundler-audit-0.7.0.1 | data/ruby-advisory-db/gems/rubygems-update/CVE-2015-3900.yml |