CVE-2015-4020
Publication date 25 August 2015
Last updated 24 July 2024
Ubuntu priority
RubyGems 2.0.x before 2.0.17, 2.2.x before 2.2.5, and 2.4.x before 2.4.8 does not validate the hostname when fetching gems or making API requests, which allows remote attackers to redirect requests to arbitrary domains via a crafted DNS SRV record with a domain that is suffixed with the original domain name, aka a "DNS hijack attack." NOTE: this vulnerability exists because to an incomplete fix for CVE-2015-3900.
Status
Package | Ubuntu Release | Status |
---|---|---|
jruby | ||
14.04 LTS trusty |
Not affected
|
|
libgems-ruby | ||
14.04 LTS trusty | Not in release | |
ruby1.8 | ||
14.04 LTS trusty | Not in release | |
ruby1.9.1 | ||
14.04 LTS trusty | Not in release | |
ruby2.1 | ||
14.04 LTS trusty | Not in release | |
ruby2.2 | ||
14.04 LTS trusty | Not in release | |
rubygems | ||
14.04 LTS trusty | Not in release | |