CVE-2015-3900
MEDIUM severity · CVSS 5 · CWE-254
5CVSS MEDIUM
Summary
RubyGems 2.0.x before 2.0.16, 2.2.x before 2.2.4, and 2.4.x before 2.4.7 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record, aka a "DNS hijack attack."
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impact—
Availability impactNone
Exploit probability (EPSS)9%
AV:N/AC:L/Au:N/C:N/I:P/A:N
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Official patch: http://blog.rubygems.org/2015/05/14/CVE-2015-3900.html ↗
Additional information
- NVD record
- http://blog.rubygems.org/2015/05/14/CVE-2015-3900.htmlPatch
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163502.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/163600.html
- http://lists.fedoraproject.org/pipermail/package-announce/2015-August/164236.html
- http://rhn.redhat.com/errata/RHSA-2015-1657.htmlAdvisory
- http://www.openwall.com/lists/oss-security/2015/06/26/2Advisory
- http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.htmlAdvisory
- http://www.securityfocus.com/bid/75482