Get a Pentest and security assessment of your IT network.

2021-current

CVE-2015-4020 – RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8

RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a domain that is suffixed with the original domain name, aka a “DNS hijack attack.” NOTE: this vulnerability exists because to an incomplete fix for CVE-2015-3900.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-4020

Reference (s):

  • BID:75431
  • URL: http://www.securityfocus.com/bid/75431
  • http://blog.rubygems.org/2015/06/08/2.2.5-released.html
  • http://blog.rubygems.org/2015/06/08/2.4.8-released.html
  • http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html
Related posts
2021-current

CVE-2004-1715 - Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 all

2021-current

CVE-2014-4743 - Multiple cross-site scripting (XSS) vulnerabilities in (1) search_ajax.tp

2021-current

CVE-2014-9838 - magick/cache.c in ImageMagick 6.8.9-9 allows remote attackers to cause a

2021-current

CVE-2020-10447 - The way URIs are handled in admin/header.php in Chadha PHPKB Standard Mul