CVE-2007-0469

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/01/2007
Last modified:
09/04/2025

Description

The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rubyforge:rubygems:*:*:*:*:*:*:*:* 0.9.0 (including)
cpe:2.3:a:rubyforge:rubygems:0.8.11:*:*:*:*:*:*:*