Release date:
Updated on:
Affected Systems:
Rubygems Fileutils
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58222
RubyGems Fileutils is a set of tools that extract metadata of various file types.
Multiple insecure temporary file processing vulnerabilities exist in Fileutils implementation. Local attackers can exploit this vulnerability to execute symbolic link attacks to overwrite any files in the affected application context.
<* Source: Larry W. Cashdollar (lwc@vapid.dhs.org)
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Rubygems
--------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Https://rubygems.org/gems/fileutils