CVE-2013-0334
Publication date 31 October 2014
Last updated 24 July 2024
Ubuntu priority
Description
Bundler before 1.7, when multiple top-level source lines are used, allows remote attackers to install arbitrary gems by creating a gem with the same name as another gem in a different source.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| bundler | ||
| 18.04 LTS bionic |
Not affected
|
|
| 16.04 LTS xenial |
Not affected
|
|
| 14.04 LTS trusty | Not in release | |