<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T04:54:04.163027+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2019-03332</id>
    <title>bdu:2019-03332</title>
    <updated>2026-10-03T04:54:04.234927+00:00</updated>
    <content>bdu:2019-03332</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2019-03332"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2019-06349</id>
    <title>cnvd-2019-06349</title>
    <updated>2026-10-03T04:54:04.234971+00:00</updated>
    <content>cnvd-2019-06349</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2019-06349"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-52061</id>
    <title>EUVD-2026-52061</title>
    <updated>2026-10-03T04:54:04.234986+00:00</updated>
    <content>EUVD-2026-52061</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-52061"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-8320</id>
    <title>fkie_cve-2019-8320</title>
    <updated>2026-10-03T04:54:04.234997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-8320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5x32-c9mf-49cc</id>
    <title>GHSA-5x32-c9mf-49cc — RubyGems Delete directory using symlink when decompressing tar</title>
    <updated>2026-10-03T04:54:04.235029+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> RubyGems: rubygems-update</p>
<p>A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5x32-c9mf-49cc"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-8320</id>
    <title>gsd-2019-8320</title>
    <updated>2026-10-03T04:54:04.235058+00:00</updated>
    <content>gsd-2019-8320</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-8320"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2019:1771-1</id>
    <title>openSUSE-SU-2019:1771-1 — Security update for ruby-bundled-gems-rpmhelper, ruby2.5</title>
    <updated>2026-10-03T04:54:04.235070+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ruby-bundled-gems-rpmhelper, ruby2.5</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2019:1771-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2019:1148</id>
    <title>RHSA-2019:1148 — Red Hat Security Advisory: rh-ruby25-ruby security, bug fix, and enhancement update</title>
    <updated>2026-10-03T04:54:04.235100+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>rubygems: Delete directory using symlink when decompressing tar rubygems: Escape sequence injection vulnerability in verbose rubygems: Escape sequence injection vulnerability in gem owner rubygems: Escape sequence injection vulnerability in API response handling rubygems: Installing a malicious gem may lead to arbitrary code execution rubygems: Escape sequence injection vulnerability in errors</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2019:1148"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2019:1804-1</id>
    <title>SUSE-SU-2019:1804-1 — Security update for ruby-bundled-gems-rpmhelper, ruby2.5</title>
    <updated>2026-10-03T04:54:04.235126+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for ruby-bundled-gems-rpmhelper, ruby2.5</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2019:1804-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-8320</id>
    <title>UBUNTU-CVE-2019-8320</title>
    <updated>2026-10-03T04:54:04.235152+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: ruby1.9.1, Ubuntu:14.04:LTS: ruby2.0, Ubuntu:16.04:LTS: ruby2.3, Ubuntu:18.04:LTS: ruby2.5, Ubuntu:18.04:LTS: jruby</p>
<p>A Directory Traversal issue was discovered in RubyGems 2.7.6 and later through 3.0.2. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. If that destination was hidden behind a symlink, a malicious gem could delete arbitrary files on the user's machine, presuming the attacker could guess at paths. Given how frequently gem is run as sudo, and how predictable paths are on modern systems (/tmp, /usr, etc.), this could likely lead to data loss or an unusable system.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-8320"/>
  </entry>
</feed>
