CVE-2018-6914
Last modified
CVE-2018-6914 is a vulnerability of currently unknown severity. Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.. EPSS estimates a 10.55% chance of exploitation in the next 30 days.
Description
Directory traversal vulnerability in the Dir.mktmpdir method in the tmpdir library in Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x before 2.5.1, and 2.6.0-preview1 might allow attackers to create arbitrary directories or files via a .. (dot dot) in the prefix argument.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Ruby-Lang | Ruby | >= 2.2.0, < 2.2.10 | — |
| Ruby-Lang | Ruby | >= 2.3.0, < 2.3.7 | — |
| Ruby-Lang | Ruby | >= 2.4.0, < 2.4.4 | — |
| Ruby-Lang | Ruby | >= 2.5.0, < 2.5.1 | — |
| Ruby-Lang | Ruby | 2.6.0 | Preview1 |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 17.10 | — |
| Debian | Debian Linux | 7.0 | — |
| Debian | Debian Linux | 8.0 | — |
| Debian | Debian Linux | 9.0 | — |
| Redhat | Enterprise Linux | 6.0 | — |
| Redhat | Enterprise Linux | 7.0 | — |
| Redhat | Enterprise Linux | 7.4 | — |
| Redhat | Enterprise Linux | 7.5 | — |
| Redhat | Enterprise Linux | 7.6 | — |
References
- http://www.securityfocus.com/bid/103686Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042004Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3729Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3730Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3731Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00023.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00024.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3626-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4259Third Party Advisory
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-2-10-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-3-7-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-4-4-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-5-1-released/Patch, Release Notes
- http://www.securityfocus.com/bid/103686Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1042004Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2018:3729Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3730Third Party Advisory
- https://access.redhat.com/errata/RHSA-2018:3731Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00023.htmlThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/04/msg00024.htmlMailing List, Third Party Advisory
- https://lists.debian.org/debian-lts-announce/2018/07/msg00012.htmlMailing List, Third Party Advisory
- https://usn.ubuntu.com/3626-1/Third Party Advisory
- https://www.debian.org/security/2018/dsa-4259Third Party Advisory
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-2-10-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-3-7-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-4-4-released/Patch, Release Notes
- https://www.ruby-lang.org/en/news/2018/03/28/ruby-2-5-1-released/Patch, Release Notes
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-6914?
How severe is CVE-2018-6914?
How do I fix CVE-2018-6914?
Are you affected by CVE-2018-6914?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
