rubyzip
Official Rubyzip repository
Activity
- Latest release
- 1w ago
- Total releases
- 53
- Cadence
- ~42 days
- Last 12 months
- 9
Reach
- Downloads
- 780.5M
- Stars
- 1.4k
Details
- License
- BSD-2-Clause
- First release
- Mar 03, 2005
| Version | Released | |
|---|---|---|
3.6.0
minor
|
3.6.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
3.5.0
minor
|
3.5.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
3.4.1
patch
|
3.4.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
3.4.0
minor
|
3.4.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
3.3.1
patch
|
3.3.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
3.3.0
minor
|
3.3.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
3.2.2
patch
|
3.2.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
3.2.1
patch
|
3.2.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
3.2.0
minor
|
3.2.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
3.1.1
patch
|
3.1.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
3.1.0
minor
|
3.1.0
minor
Dependencies (8)
Changelog
Compare changes
|
|
3.0.2
patch
|
3.0.2
patch
Dependencies (8)
Changelog
Compare changes
|
|
3.0.1
patch
|
3.0.1
patch
Dependencies (8)
Changelog
Compare changes
|
|
3.0.0
major
|
3.0.0
major
Dependencies (8)
Changelog
Compare changes
|
|
3.0.0.rc2
pre
|
3.0.0.rc2
pre
Dependencies (8)
Changelog
Compare changes
|
|
3.0.0.rc1
pre
|
3.0.0.rc1
pre
Dependencies (8)
Changelog
Compare changes
|
|
2.4.1
minor
| ||
2.4.rc1
pre
| ||
3.0.0.alpha
pre
|
3.0.0.alpha
pre
Dependencies (8)
Changelog
Compare changes
|
|
2.3.2
patch
| ||
2.3.1
patch
| ||
2.3.0
minor
| ||
2.2.0
minor
| ||
2.1.0
minor
| ||
2.0.0
major
| ||
1.3.0
minor
| ||
1.2.4
patch
1 CVE
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.3
patch
1 CVE
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.2
patch
1 CVE
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.1
patch
2 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.2.0
minor
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.7
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.6
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.5
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.4
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.3
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.2
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.1
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.1.0
minor
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.0
major
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
1.0.0.beta1
pre
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.9
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.8
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.7
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.6.1
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.5
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.4
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.9.1
minor
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.12
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev | ||
0.5.11
patch
3 CVEs
CVE-2019-16892
GHSA-5m2v-hc64-56h6
Sep 30, 2019
Rubyzip denial of service
5.5
/ 10
Medium
Local
Low
None
Required
Unchanged
None
None
High
In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption). Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 15 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
Fixed in
1.3.0
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2018-1000544
GHSA-vqcq-mrmw-mcmg
Sep 06, 2018
Rubyzip gem contains a Directory Traversal vulnerability in zip file component
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
rubyzip gem rubyzip version 1.2.1 and earlier contains a Directory Traversal vulnerability in Zip::File component that can result in write arbitrary files to the filesystem. This attack appear to be exploitable via If a site allows uploading of .zip files , an attacker can upload a malicious file that contains symlinks or files with absolute pathnames "../" to write arbitrary files to the filesystem.. This is similar to CVE-2017-5946 which was patched in 1.2.1 but the fix in that case was incomplete. Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 12 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
1.2.1
Fixed in
1.2.2
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2017-5946
GHSA-gcqq-w6gr-h9j9
Oct 24, 2017
Directory traversal vulnerability in RubyZip
9.8
/ 10
Critical
Network
Low
None
None
Unchanged
High
High
High
The Affected versions
0.5.11
0.5.12
0.5.7
0.5.8
0.5.9
0.9.1
0.9.4
0.9.5
0.9.6.1
0.9.7
0.9.8
0.9.9
+ 11 more Show less
1.0.0
1.0.0.beta1
1.1.0
1.1.1
1.1.2
1.1.3
1.1.4
1.1.5
1.1.6
1.1.7
1.2.0
Fixed in
1.2.1
References
Updated Feb 16, 2024 · Source: OSV.dev |