9.3
CVSSv2

CVE-2007-0469

Published: 24/01/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 828
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

The extract_files function in installer.rb in RubyGems prior to 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote malicious users to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.

Vulnerable Product Search on Vulmon Subscribe to Product

rubyforge rubygems 0.8.11

rubyforge rubygems