Command injection in RubyGems - CVE-2015-9096
Published: September 6, 2017
Vulnerability identifier: #VU8122
CSH Severity: Low
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2015-9096
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary commands on the target system.
The weakness exists due to improper validation of user supplied input in the Net::SMTP function. A remote attacker can use CRLF sequences in a RCPT TO or MAIL FROM command and execute arbitrary SMTP commands on the system.
The weakness exists due to improper validation of user supplied input in the Net::SMTP function. A remote attacker can use CRLF sequences in a RCPT TO or MAIL FROM command and execute arbitrary SMTP commands on the system.
Affected software
RubyGems
Debian Linux
Amazon Linux AMI
Fedora
EMC Integrated Data Protection Appliance
Dell EMC Data Protection Search
ruby
Debian Linux
Amazon Linux AMI
Fedora
EMC Integrated Data Protection Appliance
Dell EMC Data Protection Search
ruby
How to mitigate CVE-2015-9096
Update to version 2.4.0.
EMC Integrated Data Protection Appliance - update to 2.7.1
Dell EMC Data Protection Search - update to 19.6.0
ruby - addressed in versions 2.3.4-63.fc24, 2.3.4-63.fc25
Dell EMC Data Protection Search - update to 19.6.0
ruby - addressed in versions 2.3.4-63.fc24, 2.3.4-63.fc25