[ALAS-2014-447] Amazon Linux AMI 2014.03 - ALAS-2014-447: medium priority package update for ruby19

Severity Medium
Affected Packages 22
CVEs 1

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2014-8090:
1159927:
CVE-2014-8090 ruby: REXML incomplete fix for CVE-2014-8080

Package Affected Version
pkg:rpm/amazonlinux/rubygems19?arch=noarch&distro=amazonlinux-1 < 1.8.23.2-32.64.amzn1
pkg:rpm/amazonlinux/rubygems19-devel?arch=noarch&distro=amazonlinux-1 < 1.8.23.2-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-rdoc?arch=noarch&distro=amazonlinux-1 < 3.9.5-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-rake?arch=noarch&distro=amazonlinux-1 < 0.9.2.2-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-minitest?arch=noarch&distro=amazonlinux-1 < 2.5.1-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-json?arch=x86_64&distro=amazonlinux-1 < 1.5.5-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-json?arch=i686&distro=amazonlinux-1 < 1.5.5-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-io-console?arch=x86_64&distro=amazonlinux-1 < 0.3-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-io-console?arch=i686&distro=amazonlinux-1 < 0.3-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-bigdecimal?arch=x86_64&distro=amazonlinux-1 < 1.1.0-32.64.amzn1
pkg:rpm/amazonlinux/rubygem19-bigdecimal?arch=i686&distro=amazonlinux-1 < 1.1.0-32.64.amzn1
pkg:rpm/amazonlinux/ruby19?arch=x86_64&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19?arch=i686&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-libs?arch=x86_64&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-libs?arch=i686&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-irb?arch=noarch&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-doc?arch=x86_64&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-doc?arch=i686&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-devel?arch=x86_64&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-devel?arch=i686&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-debuginfo?arch=x86_64&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
pkg:rpm/amazonlinux/ruby19-debuginfo?arch=i686&distro=amazonlinux-1 < 1.9.3.551-32.64.amzn1
ID
ALAS-2014-447
Severity
medium
URL
https://alas.aws.amazon.com/ALAS-2014-447.html
Published
2014-11-13T17:25:00
(9 years ago)
Modified
2014-11-16T13:32:00
(9 years ago)
Rights
Amazon Linux Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/rubygems19?arch=noarch&distro=amazonlinux-1 amazonlinux rubygems19 < 1.8.23.2-32.64.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/rubygems19-devel?arch=noarch&distro=amazonlinux-1 amazonlinux rubygems19-devel < 1.8.23.2-32.64.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/rubygem19-rdoc?arch=noarch&distro=amazonlinux-1 amazonlinux rubygem19-rdoc < 3.9.5-32.64.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/rubygem19-rake?arch=noarch&distro=amazonlinux-1 amazonlinux rubygem19-rake < 0.9.2.2-32.64.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/rubygem19-minitest?arch=noarch&distro=amazonlinux-1 amazonlinux rubygem19-minitest < 2.5.1-32.64.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/rubygem19-json?arch=x86_64&distro=amazonlinux-1 amazonlinux rubygem19-json < 1.5.5-32.64.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/rubygem19-json?arch=i686&distro=amazonlinux-1 amazonlinux rubygem19-json < 1.5.5-32.64.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/rubygem19-io-console?arch=x86_64&distro=amazonlinux-1 amazonlinux rubygem19-io-console < 0.3-32.64.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/rubygem19-io-console?arch=i686&distro=amazonlinux-1 amazonlinux rubygem19-io-console < 0.3-32.64.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/rubygem19-bigdecimal?arch=x86_64&distro=amazonlinux-1 amazonlinux rubygem19-bigdecimal < 1.1.0-32.64.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/rubygem19-bigdecimal?arch=i686&distro=amazonlinux-1 amazonlinux rubygem19-bigdecimal < 1.1.0-32.64.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby19?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby19 < 1.9.3.551-32.64.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby19?arch=i686&distro=amazonlinux-1 amazonlinux ruby19 < 1.9.3.551-32.64.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby19-libs?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby19-libs < 1.9.3.551-32.64.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby19-libs?arch=i686&distro=amazonlinux-1 amazonlinux ruby19-libs < 1.9.3.551-32.64.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby19-irb?arch=noarch&distro=amazonlinux-1 amazonlinux ruby19-irb < 1.9.3.551-32.64.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/ruby19-doc?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby19-doc < 1.9.3.551-32.64.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby19-doc?arch=i686&distro=amazonlinux-1 amazonlinux ruby19-doc < 1.9.3.551-32.64.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby19-devel?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby19-devel < 1.9.3.551-32.64.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby19-devel?arch=i686&distro=amazonlinux-1 amazonlinux ruby19-devel < 1.9.3.551-32.64.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby19-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby19-debuginfo < 1.9.3.551-32.64.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby19-debuginfo?arch=i686&distro=amazonlinux-1 amazonlinux ruby19-debuginfo < 1.9.3.551-32.64.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...