The netaddr gem before 2.0.4 for Ruby has misconfigured file permissions, such that a gem install may result in 0777 permissions in the target filesystem.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netaddr | Netaddr_project | 1.5.0 (including) | 1.5.3 (excluding) |
Netaddr | Netaddr_project | 2.0 (including) | 2.0.4 (excluding) |
Ruby-netaddr | Ubuntu | bionic | * |
Ruby-netaddr | Ubuntu | disco | * |
Ruby-netaddr | Ubuntu | eoan | * |
Ruby-netaddr | Ubuntu | groovy | * |
Ruby-netaddr | Ubuntu | hirsute | * |
Ruby-netaddr | Ubuntu | impish | * |
Ruby-netaddr | Ubuntu | kinetic | * |
Ruby-netaddr | Ubuntu | lunar | * |
Ruby-netaddr | Ubuntu | mantic | * |
Ruby-netaddr | Ubuntu | trusty | * |