CVE-2007-0469

Publication date 24 January 2007

Last updated 24 July 2024


Ubuntu priority

The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.

Status

No maintained releases are affected by this CVE.

Package Ubuntu Release Status
libgems-ruby 8.04 LTS hardy
Fixed 0.9.4-1ubuntu1
7.10 gutsy
Fixed 0.9.4-1ubuntu1
7.04 feisty Ignored end of life, was needed
6.10 edgy Not in release
6.06 LTS dapper Not in release