Project

General

Profile

Actions

Feature #1800

closed

rubygems can replace system executable files

Added by znz (Kazuhiro NISHIYAMA) almost 15 years ago. Updated over 12 years ago.

Status:
Closed
Target version:
[ruby-core:24472]

Description

=begin
Japanese blog http://wota.jp/ac/?date=20090604#p01 says,
gem has bin/ls and Gem::Specification#executables= ["ls"],
rubygem overwrites /usr/bin/ls without confirming.

I think this is potential security risk.
=end

Actions

Also available in: Atom PDF

Like0
Like0Like0Like0Like0Like0Like0Like0Like0Like0Like0Like0Like0Like0Like0Like0