Command injection in Ruby - CVE-2017-17405

 

Command injection in Ruby - CVE-2017-17405

Published: December 22, 2017 / Updated: June 17, 2021


Vulnerability identifier: #VU9718
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2017-17405
CWE-ID: CWE-77
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands on the target system.

The weakness exists due to flaws in the Net::FTP. A remote attacker can inject and execute arbitrary commands with elevated privileges.

Successful exploitation of the vulnerability may result in system compromise.

Affected software

Ruby
Gentoo Linux
Debian Linux
Red Hat Enterprise Linux Server
Red Hat Enterprise Linux for Scientific Computing
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux Desktop
Red Hat Enterprise Linux Workstation
Red Hat Enterprise Linux EUS Compute Node
Red Hat Enterprise Linux for Power
macOS
Slackware Linux
Ubuntu
EMC Integrated Data Protection Appliance
ruby (Alpine package)
rh-ruby22-ruby (Red Hat package)
rh-ruby23-ruby (Red Hat package)
rh-ruby24-ruby (Red Hat package)
Dell EMC Data Protection Search

How to mitigate CVE-2017-17405

Update to version 2.2.9, 2.3.6, 2.4.3 or later.

EMC Integrated Data Protection Appliance - update to 2.7.1
ruby (Alpine package) - update to 2.2.9-r0
Dell EMC Data Protection Search - update to 19.6.0
rh-ruby22-ruby (Red Hat package) - addressed in versions 2.2.9-19.el6, 2.2.9-19.el7
rh-ruby23-ruby (Red Hat package) - addressed in versions 2.3.6-67.el6, 2.3.6-67.el7
rh-ruby24-ruby (Red Hat package) - addressed in versions 2.4.3-90.el6, 2.4.3-90.el7

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins