[openSUSE-SU-2020:0586-1] Security update for ruby2.5

Severity Moderate
Affected Packages 7
CVEs 2

Security update for ruby2.5

This update for ruby2.5 to version 2.5.8 fixes the following issues:

  • CVE-2020-10663: Unsafe Object Creation Vulnerability in JSON (bsc#1167244).
  • CVE-2020-10933: Heap exposure vulnerability in the socket library (bsc#1168938).

This update was imported from the SUSE:SLE-15:Update update project.

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/opensuse/ruby2.5?arch=x86_64&distro=opensuse-leap-15.1 opensuse ruby2.5 < 2.5.8-lp151.4.9.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/ruby2.5-stdlib?arch=x86_64&distro=opensuse-leap-15.1 opensuse ruby2.5-stdlib < 2.5.8-lp151.4.9.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/ruby2.5-doc?arch=x86_64&distro=opensuse-leap-15.1 opensuse ruby2.5-doc < 2.5.8-lp151.4.9.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/ruby2.5-doc-ri?arch=noarch&distro=opensuse-leap-15.1 opensuse ruby2.5-doc-ri < 2.5.8-lp151.4.9.1 opensuse-leap-15.1 noarch
Affected pkg:rpm/opensuse/ruby2.5-devel?arch=x86_64&distro=opensuse-leap-15.1 opensuse ruby2.5-devel < 2.5.8-lp151.4.9.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/ruby2.5-devel-extra?arch=x86_64&distro=opensuse-leap-15.1 opensuse ruby2.5-devel-extra < 2.5.8-lp151.4.9.1 opensuse-leap-15.1 x86_64
Affected pkg:rpm/opensuse/libruby2_5-2_5?arch=x86_64&distro=opensuse-leap-15.1 opensuse libruby2_5-2_5 < 2.5.8-lp151.4.9.1 opensuse-leap-15.1 x86_64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...