Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
RubyGems 'installer.rb' extract_files函数拒绝服务攻击漏洞
Vulnerability Description
RubyGems 0.9.1之前版本的installer.rb中的extract_files函数没有在重写文件前确认这些文件是否存在,这使得用户协助式远程攻击者可以借助特制的GEM信息包,重写任意文件,引起拒绝服务攻击或执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A