Synopsis: Moderate: rubygem-bundler and rubygem-thor security, bug fix, and enhancement update Advisory ID: SLSA-2015:2180-7 Issue Date: 2015-11-19 CVE Numbers: CVE-2013-0334 -- A flaw was found in the way Bundler handled gems available from multiple sources. An attacker with access to one of the sources could create a malicious gem with the same name, which they could then use to trick a user into installing, potentially resulting in execution of code from the attacker-supplied malicious gem. (CVE-2013-0334) Bundler has been upgraded to upstream version 1.7.8 and Thor has been upgraded to upstream version 1.19.1, both of which provide a number of bug fixes and enhancements over the previous versions. -- SL7 noarch rubygem-bundler-1.7.8-3.el7.noarch.rpm rubygem-thor-0.19.1-1.el7.noarch.rpm rubygem-bundler-doc-1.7.8-3.el7.noarch.rpm rubygem-thor-doc-0.19.1-1.el7.noarch.rpm - Scientific Linux Development Team