Description
RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: 2.3.6 and earlier, Ruby 2.4 series: 2.4.3 and earlier, Ruby 2.5 series: 2.5.0 and earlier, prior to trunk revision 62422 contains a infinite loop caused by negative size vulnerability in ruby gem package tar header that can result in a negative size could cause an infinite loop.. This vulnerability appears to have been fixed in 2.7.6.
Remediation
References
Related Vulnerabilities
WordPress Plugin Learning Courses Privilege Escalation (4.7)
Squid Improper Input Validation Vulnerability (CVE-2021-33620)
WordPress Plugin Print, PDF, Email by PrintFriendly Multiple Unspecified Vulnerabilities (3.5.2)
Magento Improper Privilege Management Vulnerability (CVE-2020-9630)
WordPress Plugin WP Maintenance Mode Cross-Site Scripting (2.2.3)