From 35de2bdfc4cfe2406e03ec13f8a027a9f0990737 Mon Sep 17 00:00:00 2001 From: Al Snow <43523+jasnow@users.noreply.github.com> Date: Mon, 5 Oct 2026 13:45:24 -0400 Subject: [PATCH] Added more info on 1 existing advisory --- gems/backup_checksum/CVE-2014-4993.yml | 35 ++++++++++++++++++++++++++ 1 file changed, 35 insertions(+) diff --git a/gems/backup_checksum/CVE-2014-4993.yml b/gems/backup_checksum/CVE-2014-4993.yml index 9ae6d7cec9..c287f28c50 100644 --- a/gems/backup_checksum/CVE-2014-4993.yml +++ b/gems/backup_checksum/CVE-2014-4993.yml @@ -12,4 +12,39 @@ description: | that is triggered as the program displays password information in plaintext in the process list. This may allow a local attacker to gain access to password information. +cvss_v2: 2.1 cvss_v3: 7.8 +related: + url: + - https://nvd.nist.gov/vuln/detail/CVE-2014-4993 + - https://rubygems.org/gems/backup_checksum/versions/3.0.23 + - https://my.diffend.io/gems/backup_checksum/3.0.23 + - http://www.openwall.com/lists/oss-security/2014/07/17/5 + - http://www.openwall.com/lists/oss-security/2014/07/07/12 + - http://www.vapid.dhs.org/advisories/backup_checksum-3.0.23.html + - https://github.com/backup/backup + - http://rubygems.org/gems/backup + - https://backup.github.io/backup/v4/release-notes + - https://github.com/advisories/GHSA-wr5j-q359-6vr2 +notes: | + - cvss_v3 and cvss_v2 from nvd.nist.gov URL. + - nvd.nist.gov says 3.0.23 contains vulnerability. + - This gem ONLY has one release 3.0.23 (Mar.9,2012) so never patched. + - Rubygems.org's Homepage points back to Rubygems.org URL. + - Rubygems.org gem Description: "It is a clone of + http://rubygems.org/gems/backup with checksum added" + - https://github.com/backup/backup + - http://rubygems.org/gems/backup (last release on 6/5/2020) + - Source Code points to wrong URL. Use HomePage. + - https://backup.github.io/backup/v4/release-notes + - Last commit on 11/6/2023. + - NOTE: Under https://backup.github.io/backup/v4, I found: + "Project Status: Maintenance-Only + * This project is not under active development, although we + will continue to provide support for current users, and at + least one more maintenance release: version 5.0. The version 5.0 + release will include support for Ruby 2.4, and various other + fixes. Future releases of Backup will only include bug fixes. + * If you use this project and would like to develop it further, + please introduce yourself on the maintainers wanted ticket." + - THEREFORE one release/never patched.