CVE-2007-0469

NameCVE-2007-0469
DescriptionThe extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs408299

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
libgems-rubysource(unstable)0.9.3-1low408299

Notes

[etch] - libgems-ruby <no-dsa> (Minor issue, needs implicit trust on installed data)

Search for package or bug name: Reporting problems