Command injection in RubyGems - CVE-2015-9096

 

Command injection in RubyGems - CVE-2015-9096

Published: September 6, 2017


Vulnerability identifier: #VU8122
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-9096
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The weakness exists due to improper validation of user supplied input in the Net::SMTP function. A remote attacker can use CRLF sequences in a RCPT TO or MAIL FROM command and execute arbitrary SMTP commands on the system.

Affected software

RubyGems
Debian Linux
Amazon Linux AMI
Fedora
EMC Integrated Data Protection Appliance
Dell EMC Data Protection Search
ruby

How to mitigate CVE-2015-9096

Update to version 2.4.0.

EMC Integrated Data Protection Appliance - update to 2.7.1
Dell EMC Data Protection Search - update to 19.6.0
ruby - addressed in versions 2.3.4-63.fc24, 2.3.4-63.fc25

External References

Related Security Bulletins