Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

January 31st, 2013, 10:44 GMT · By

BLOG

RubyGems Put in Maintenance Mode After User Uploaded Malicious Gem

SHARE:

Adjust text size:


RubyGems hacked Enlarge picture - RubyGems hacked
The popular Ruby package manager website RubyGems (rubygems.org) has been placed in maintenance mode after owners noticed that a malicious gem which exploited a YAML parsing vulnerability was uploaded by a user.

The vulnerability in question can be used to execute arbitrary code and even gain access to sensitive data, including credentials needed to tamper with gems.

The site’s administrators immediately disabled deploys of Ruby applications and started checking the other gems for signs of tampering.

In the latest update, posted a few hours ago, RubyGems representatives revealed that 90% of the gems had been verified.

Apparently, the vulnerability exploited by the malicious gem has been reported to RubyGems around one week ago by an expert using the handle "blambeau." Another user, "Postmodern," wrote a proof-of-concept for it and posted it on a private chat room.

Someone took the POC and used it to demonstrate the severity of the issue.

TELL US WHAT YOU THINK:

1,177 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Uzbekistan’s National Television Hacked, Accused of Spreading Lies

Emerald City Comicon Website Hacked, All Backup Files Deleted

Man Arrested for Hacking Indonesian President’s Site, Faces 12 Years in Prison

Hacker Gains Access to 7 ESA Databases by Leveraging Blind SQL Injection Flaw

27-Year-Old Hacker Accused of Blackmailing Women Arrested by the FBI

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM