Ubuntu Security Notice USN-3553-1

Discussion in 'News Aggregator' started by Packet Storm, 1 Feb 2018.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3553-1 - It was discovered that Ruby failed to validate specification names. An attacker could possibly use a maliciously crafted gem to potentially overwrite any file on the filesystem. It was discovered that Ruby was vulnerable to a DNS hijacking vulnerability. An attacker could use this to possibly force the RubyGems client to download and install gems from a server that the attacker controls. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...