~ubuntu-security/ubuntu-cve-tracker/master

1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
Candidate: CVE-2013-0334
PublicDate: 2014-10-31
References:
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0334
Description:
 Bundler before 1.7, when multiple top-level source lines are used, allows
 remote attackers to install arbitrary gems by creating a gem with the same
 name as another gem in a different source.
Ubuntu-Description:
Notes:
Bugs:
Priority: medium
Discovered-by:
Assigned-to:

Patches_bundler:
upstream_bundler: released (1.7.2-1)
lucid_bundler: DNE
precise_bundler: DNE
precise/esm_bundler: DNE
trusty_bundler: needed
utopic_bundler: ignored (reached end-of-life)
vivid_bundler: not-affected (1.7.4-1)
vivid/stable-phone-overlay_bundler: DNE
vivid/ubuntu-core_bundler: DNE
wily_bundler: not-affected (1.10.6-1)
xenial_bundler: not-affected (1.10.6-2)
yakkety_bundler: not-affected (1.10.6-2)
zesty_bundler: not-affected (1.10.6-2)
devel_bundler: not-affected (1.10.6-2)