{"title":" RubyGems 0.9.0 and earlier installation exploit","provider_name":"Hatena Blog","author_url":"https://blog.hatena.ne.jp/hiro-ueda/","published":"2007-02-11 00:00:01","type":"rich","author_name":"hiro-ueda","width":"100%","blog_url":"https://bsdmad.hatenablog.com/","url":"https://bsdmad.hatenablog.com/entry/20070211/p2","categories":["Security","Ruby"],"version":"1.0","description":"\u67d0\u6240\u3067\u4e00\u304b\u3089 Ruby on Rails \u74b0\u5883\u3092\u4f5c\u308b\u3079\u304f\u5404\u30b5\u30a4\u30c8\u3092\u8a2a\u554f\u3057\u3066\u3044\u3066\u898b\u3064\u3051\u307e\u3057\u305f\u3002 RubyGems 0.9.0 and earlier installation exploit Problem Description:RubyGems does not check installation paths for gems before writing files.Impact:Since RubyGems packages are typically installed using root permissions, arbitrary files may be overwritte\u2026","provider_url":"https://hatena.blog","height":"190","blog_title":"BSDmad \u306e\u65e5\u8a18","html":"<iframe src=\"https://hatenablog-parts.com/embed?url=https%3A%2F%2Fbsdmad.hatenablog.com%2Fentry%2F20070211%2Fp2\" title=\" RubyGems 0.9.0 and earlier installation exploit - BSDmad \u306e\u65e5\u8a18\" class=\"embed-card embed-blogcard\" scrolling=\"no\" frameborder=\"0\" style=\"display: block; width: 100%; height: 190px; max-width: 500px; margin: 10px 0px;\"></iframe>","image_url":null}