Description
RubyGems version 2.6.12 and earlier fails to validate specification names, allowing a maliciously crafted gem to potentially overwrite any file on the filesystem.
Remediation
References
Related Vulnerabilities
Perl Other Vulnerability (CVE-2011-0761)
WordPress Plugin MP3-jPlayer Local File Disclosure (2.3)
Joomla! Core 2.5.x Remote File Inclusion (2.5.4 - 2.5.25)
WordPress Plugin Awesome Support-WordPress HelpDesk & Support Unspecified Vulnerability (6.0.7)
WordPress Plugin WP Maintenance Mode Remote Code Execution (2.0.6)