[GLSA-202003-06] Ruby: Multiple vulnerabilities
Multiple vulnerabilities have been found in Ruby, the worst of which could lead to the remote execution of arbitrary code.
Background
Ruby is an interpreted object-oriented programming language. The
elaborate standard library includes an HTTP server (“WEBRick”) and a
class for XML parsing (“REXML”).
Description
Multiple vulnerabilities have been discovered in Ruby. Please review the
CVE identifiers referenced below for details.
Impact
A remote attacker could execute arbitrary code, have unauthorized access
by bypassing intended path matching or cause a Denial of Service
condition.
Workaround
There is no known workaround at this time.
Resolution
All Ruby 2.4.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/ruby-2.4.9:2.4"
All Ruby 2.5.x users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=dev-lang/ruby-2.5.7:2.5"
Package | Affected Version |
---|---|
pkg:ebuild/dev-lang/ruby?distro=gentoo | < 2.4.9 |
pkg:ebuild/dev-lang/ruby?distro=gentoo | < 2.5.7 |
Package | Unaffected Version |
---|---|
pkg:ebuild/dev-lang/ruby?distro=gentoo | >= 2.4.9 |
pkg:ebuild/dev-lang/ruby?distro=gentoo | >= 2.5.7 |
- ID
- GLSA-202003-06
- Severity
- normal
- URL
- https://security.gentoo.org/glsa/202003-06
- Published
-
2020-03-13T00:00:00
(4 years ago) - Modified
-
2020-03-13T00:00:00
(4 years ago) - Rights
- Gentoo Foundation, Inc.
- Other Advisories
-
- ALAS-2020-1422
- ALAS2-2024-2486
- ALPINE:CVE-2019-15845
- ALPINE:CVE-2019-16201
- ALPINE:CVE-2019-16254
- ALPINE:CVE-2019-16255
- ALSA-2021:2587
- ALSA-2021:2588
- ASA-201910-2
- DSA-4586-1
- DSA-4587-1
- ELSA-2021-2587
- ELSA-2021-2588
- FREEBSD:F7FCB75C-E537-11E9-863E-B9B7AF01BA9E
- MS:CVE-2019-15845
- MS:CVE-2019-16201
- MS:CVE-2019-16254
- MS:CVE-2019-16255
- openSUSE-SU-2020:0395-1
- RHSA-2021:2587
- RHSA-2021:2588
- RLSA-2021:2587
- RLSA-2021:2588
- RUBYSEC:PUMA-2020-5247
- SUSE-SU-2020:0737-1
- SUSE-SU-2020:1570-1
- USN-4201-1
Source | # ID | Name | URL |
---|---|---|---|
CVE | CVE-2019-15845 | CVE-2019-15845 | https://nvd.nist.gov/vuln/detail/CVE-2019-15845 |
CVE | CVE-2019-16201 | CVE-2019-16201 | https://nvd.nist.gov/vuln/detail/CVE-2019-16201 |
CVE | CVE-2019-16254 | CVE-2019-16254 | https://nvd.nist.gov/vuln/detail/CVE-2019-16254 |
CVE | CVE-2019-16255 | CVE-2019-16255 | https://nvd.nist.gov/vuln/detail/CVE-2019-16255 |
Bugzilla | 696004 | Bugzilla #696004 | https://bugs.gentoo.org/show_bug.cgi?id=696004 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:ebuild/dev-lang/ruby?distro=gentoo | dev-lang | ruby | < 2.4.9 | gentoo | ||
Affected | pkg:ebuild/dev-lang/ruby?distro=gentoo | dev-lang | ruby | < 2.5.7 | gentoo | ||
Unaffected | pkg:ebuild/dev-lang/ruby?distro=gentoo | dev-lang | ruby | >= 2.4.9 | gentoo | ||
Unaffected | pkg:ebuild/dev-lang/ruby?distro=gentoo | dev-lang | ruby | >= 2.5.7 | gentoo |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |