Moderate severityNVD Advisory· Published Jan 24, 2007· Updated Apr 23, 2026
CVE-2007-0469
CVE-2007-0469
Description
The extract_files function in installer.rb in RubyGems before 0.9.1 does not check whether files exist before overwriting them, which allows user-assisted remote attackers to overwrite arbitrary files, cause a denial of service, or execute arbitrary code via crafted GEM packages.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
rubygems-updateRubyGems | < 0.9.1 | 0.9.1 |
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- rubyforge.org/frs/shownotes.phpnvdPatchVendor Advisory
- github.com/advisories/GHSA-95vx-q4c2-64grghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2007-0469ghsaADVISORY
- marc.infonvdWEB
- www.novell.com/linux/security/advisories/2007_4_sr.htmlnvdWEB
- exchange.xforce.ibmcloud.com/vulnerabilities/31688nvdWEB
- web.archive.org/web/20070210090150/http://rubyforge.org/frs/shownotes.phpghsaWEB
- web.archive.org/web/20201207172116/http://www.securityfocus.com/archive/1/458128/100/0/threadedghsaWEB
- www.securityfocus.com/archive/1/458128/100/0/threadednvd
- www.vupen.com/english/advisories/2007/0295nvd
News mentions
0No linked articles in our index yet.