[ALAS-2020-1416] Amazon Linux AMI 2014.03 - ALAS-2020-1416: medium priority package update for ruby20

Severity Medium
Affected Packages 18
CVEs 2

Package updates are available for Amazon Linux AMI that fix the following vulnerabilities:
CVE-2020-10663:
The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9, 2.5 through 2.5.7, and 2.6 through 2.6.5, has an Unsafe Object Creation Vulnerability. This is quite similar to CVE-2013-0269, but does not rely on poor garbage-collection behavior within Ruby. Specifically, use of JSON parsing methods can lead to creation of a malicious object within the interpreter, with adverse effects that are application-dependent.
1827500: CVE-2020-10663 rubygem-json: Unsafe Object Creation Vulnerability in JSON

CVE-2018-16396:
An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.
1643089: CVE-2018-16396 ruby: Tainted flags are not propagated in Array#pack and String#unpack with some directives
1643089:
CVE-2018-16396 ruby: Tainted flags are not propagated in Array#pack and String#unpack with some directives

Package Affected Version
pkg:rpm/amazonlinux/rubygems20?arch=noarch&distro=amazonlinux-1 < 2.0.14.1-1.33.amzn1
pkg:rpm/amazonlinux/rubygems20-devel?arch=noarch&distro=amazonlinux-1 < 2.0.14.1-1.33.amzn1
pkg:rpm/amazonlinux/rubygem20-psych?arch=x86_64&distro=amazonlinux-1 < 2.0.0-1.33.amzn1
pkg:rpm/amazonlinux/rubygem20-psych?arch=i686&distro=amazonlinux-1 < 2.0.0-1.33.amzn1
pkg:rpm/amazonlinux/rubygem20-io-console?arch=x86_64&distro=amazonlinux-1 < 0.4.2-1.33.amzn1
pkg:rpm/amazonlinux/rubygem20-io-console?arch=i686&distro=amazonlinux-1 < 0.4.2-1.33.amzn1
pkg:rpm/amazonlinux/rubygem20-bigdecimal?arch=x86_64&distro=amazonlinux-1 < 1.2.0-1.33.amzn1
pkg:rpm/amazonlinux/rubygem20-bigdecimal?arch=i686&distro=amazonlinux-1 < 1.2.0-1.33.amzn1
pkg:rpm/amazonlinux/ruby20?arch=x86_64&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20?arch=i686&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20-libs?arch=x86_64&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20-libs?arch=i686&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20-irb?arch=noarch&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20-doc?arch=noarch&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20-devel?arch=x86_64&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20-devel?arch=i686&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20-debuginfo?arch=x86_64&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
pkg:rpm/amazonlinux/ruby20-debuginfo?arch=i686&distro=amazonlinux-1 < 2.0.0.648-1.33.amzn1
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/amazonlinux/rubygems20?arch=noarch&distro=amazonlinux-1 amazonlinux rubygems20 < 2.0.14.1-1.33.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/rubygems20-devel?arch=noarch&distro=amazonlinux-1 amazonlinux rubygems20-devel < 2.0.14.1-1.33.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/rubygem20-psych?arch=x86_64&distro=amazonlinux-1 amazonlinux rubygem20-psych < 2.0.0-1.33.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/rubygem20-psych?arch=i686&distro=amazonlinux-1 amazonlinux rubygem20-psych < 2.0.0-1.33.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/rubygem20-io-console?arch=x86_64&distro=amazonlinux-1 amazonlinux rubygem20-io-console < 0.4.2-1.33.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/rubygem20-io-console?arch=i686&distro=amazonlinux-1 amazonlinux rubygem20-io-console < 0.4.2-1.33.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/rubygem20-bigdecimal?arch=x86_64&distro=amazonlinux-1 amazonlinux rubygem20-bigdecimal < 1.2.0-1.33.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/rubygem20-bigdecimal?arch=i686&distro=amazonlinux-1 amazonlinux rubygem20-bigdecimal < 1.2.0-1.33.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby20?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby20 < 2.0.0.648-1.33.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby20?arch=i686&distro=amazonlinux-1 amazonlinux ruby20 < 2.0.0.648-1.33.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby20-libs?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby20-libs < 2.0.0.648-1.33.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby20-libs?arch=i686&distro=amazonlinux-1 amazonlinux ruby20-libs < 2.0.0.648-1.33.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby20-irb?arch=noarch&distro=amazonlinux-1 amazonlinux ruby20-irb < 2.0.0.648-1.33.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/ruby20-doc?arch=noarch&distro=amazonlinux-1 amazonlinux ruby20-doc < 2.0.0.648-1.33.amzn1 amazonlinux-1 noarch
Affected pkg:rpm/amazonlinux/ruby20-devel?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby20-devel < 2.0.0.648-1.33.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby20-devel?arch=i686&distro=amazonlinux-1 amazonlinux ruby20-devel < 2.0.0.648-1.33.amzn1 amazonlinux-1 i686
Affected pkg:rpm/amazonlinux/ruby20-debuginfo?arch=x86_64&distro=amazonlinux-1 amazonlinux ruby20-debuginfo < 2.0.0.648-1.33.amzn1 amazonlinux-1 x86_64
Affected pkg:rpm/amazonlinux/ruby20-debuginfo?arch=i686&distro=amazonlinux-1 amazonlinux ruby20-debuginfo < 2.0.0.648-1.33.amzn1 amazonlinux-1 i686
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...