Deserialization of untrusted data in RubyGems - CVE-2017-0903
Published: October 13, 2017
Vulnerability identifier: #VU8815
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-0903
CWE-ID: CWE-502
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The weakness exists due to YAML deserialization of gem specifications. A remote attacker can inject an instance of specially crafted serialized objects, gain elevated privileges and execute arbitrary Ruby code on RubyGems.org.
Successful exploitation of the vulnerability may result in system compromise.
The weakness exists due to YAML deserialization of gem specifications. A remote attacker can inject an instance of specially crafted serialized objects, gain elevated privileges and execute arbitrary Ruby code on RubyGems.org.
Successful exploitation of the vulnerability may result in system compromise.
Affected software
RubyGems
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Ubuntu
Fedora
EMC Integrated Data Protection Appliance
Dell EMC Data Protection Search
libruby2.0 (Ubuntu package)
ruby2.0 (Ubuntu package)
rh-ruby22-ruby (Red Hat package)
rh-ruby23-ruby (Red Hat package)
ruby
Amazon Linux AMI
Debian Linux
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
Ubuntu
Fedora
EMC Integrated Data Protection Appliance
Dell EMC Data Protection Search
libruby2.0 (Ubuntu package)
ruby2.0 (Ubuntu package)
rh-ruby22-ruby (Red Hat package)
rh-ruby23-ruby (Red Hat package)
ruby
How to mitigate CVE-2017-0903
Update to version 2.6.14.
EMC Integrated Data Protection Appliance - update to 2.7.1
Dell EMC Data Protection Search - update to 19.6.0
libruby2.0 (Ubuntu package) - update to 2.0.0.484-1ubuntu2.13+esm1
ruby2.0 (Ubuntu package) - update to 2.0.0.484-1ubuntu2.13+esm1
rh-ruby22-ruby (Red Hat package) - addressed in versions 2.2.9-19.el6, 2.2.9-19.el7
rh-ruby23-ruby (Red Hat package) - addressed in versions 2.3.6-67.el6, 2.3.6-67.el7
ruby - addressed in versions 2.4.3-86.fc26, 2.4.3-86.fc27
Dell EMC Data Protection Search - update to 19.6.0
libruby2.0 (Ubuntu package) - update to 2.0.0.484-1ubuntu2.13+esm1
ruby2.0 (Ubuntu package) - update to 2.0.0.484-1ubuntu2.13+esm1
rh-ruby22-ruby (Red Hat package) - addressed in versions 2.2.9-19.el6, 2.2.9-19.el7
rh-ruby23-ruby (Red Hat package) - addressed in versions 2.3.6-67.el6, 2.3.6-67.el7
ruby - addressed in versions 2.4.3-86.fc26, 2.4.3-86.fc27
External References
Related Security Bulletins
- Remote code execution in RubyGems
- Debian update for ruby2.3
- Red Hat update for ruby
- Ubuntu update for Ruby
- Amazon Linux AMI update for ruby24, ruby22, ruby23
- Red Hat update for ruby
- Multiple vulnerabilities in Dell EMC Integrated Data Protection Appliance
- Multiple vulnerabilities in Dell EMC Data Protection Search
- Ubuntu update for ruby2.0
- Red Hat Software Collections update for rh-ruby22-ruby
- Red Hat Software Collections update for rh-ruby23-ruby
- Fedora 27 update for ruby
- Fedora 26 update for ruby