{"id":"GHSA-2xvj-j3qh-x8c3","summary":"private_address_check contains race condition","details":"The private_address_check ruby gem before 0.5.0 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition due to the address the socket uses not being checked. DNS entries with a TTL of 0 can trigger this case where the initial resolution is a public address but the subsequent resolution is a private address.","aliases":["CVE-2018-3759"],"modified":"2024-11-29T05:42:10.115216Z","published":"2018-07-31T18:13:05Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2020-06-16T20:53:26Z","nvd_published_at":null,"cwe_ids":["CWE-362"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-3759"},{"type":"WEB","url":"https://github.com/jtdowney/private_address_check/commit/4068228187db87fea7577f7020099399772bb147"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-2xvj-j3qh-x8c3"},{"type":"PACKAGE","url":"https://github.com/jtdowney/private_address_check"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/private_address_check/CVE-2018-3759.yml"}],"affected":[{"package":{"name":"private_address_check","ecosystem":"RubyGems","purl":"pkg:gem/private_address_check"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.5.0"}]}],"versions":["0.1.0","0.2.0","0.3.0","0.4.0","0.4.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2018/07/GHSA-2xvj-j3qh-x8c3/GHSA-2xvj-j3qh-x8c3.json"}}],"schema_version":"1.9.0"}