[ELSA-2014-1912] ruby security update
Severity
Moderate
Affected Packages
15
CVEs
3
[2.0.0.353-22]
- Fix REXML billion laughs attack via parameter entity expansion
(CVE-2014-8080).
Resolves: rhbz#1163998
- REXML incomplete fix for CVE-2014-8080 (CVE-2014-8090).
Resolves: rhbz#1163998
[2.0.0.353-21]
- Fix off-by-one stack-based buffer overflow in the encodes() function
(CVE-2014-4975)
Resolves: rhbz#1163998
[2.0.0.353-21]
- Fix FTBFS with new tzdata
Related: rhbz#1163998
- ID
- ELSA-2014-1912
- Severity
- moderate
- URL
- https://linux.oracle.com/errata/ELSA-2014-1912.html
- Published
-
2014-11-26T00:00:00
(9 years ago) - Modified
-
2014-11-26T00:00:00
(9 years ago) - Rights
- Copyright 2014 Oracle, Inc.
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
elsa | ELSA-2014-1912 | http://linux.oracle.com/errata/ELSA-2014-1912.html | |
CVE | CVE-2014-8080 | http://linux.oracle.com/cve/CVE-2014-8080 | |
CVE | CVE-2014-8090 | http://linux.oracle.com/cve/CVE-2014-8090 | |
CVE | CVE-2014-4975 | http://linux.oracle.com/cve/CVE-2014-4975 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/oraclelinux/rubygems?distro=oraclelinux-7.0 | oraclelinux | rubygems | < 2.0.14-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/rubygems-devel?distro=oraclelinux-7.0 | oraclelinux | rubygems-devel | < 2.0.14-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/rubygem-rdoc?distro=oraclelinux-7.0 | oraclelinux | rubygem-rdoc | < 4.0.0-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/rubygem-rake?distro=oraclelinux-7.0 | oraclelinux | rubygem-rake | < 0.9.6-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/rubygem-psych?distro=oraclelinux-7.0 | oraclelinux | rubygem-psych | < 2.0.0-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/rubygem-minitest?distro=oraclelinux-7.0 | oraclelinux | rubygem-minitest | < 4.3.2-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/rubygem-json?distro=oraclelinux-7.0 | oraclelinux | rubygem-json | < 1.7.7-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/rubygem-io-console?distro=oraclelinux-7.0 | oraclelinux | rubygem-io-console | < 0.4.2-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/rubygem-bigdecimal?distro=oraclelinux-7.0 | oraclelinux | rubygem-bigdecimal | < 1.2.0-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/ruby?distro=oraclelinux-7.0 | oraclelinux | ruby | < 2.0.0.353-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/ruby-tcltk?distro=oraclelinux-7.0 | oraclelinux | ruby-tcltk | < 2.0.0.353-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/ruby-libs?distro=oraclelinux-7.0 | oraclelinux | ruby-libs | < 2.0.0.353-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/ruby-irb?distro=oraclelinux-7.0 | oraclelinux | ruby-irb | < 2.0.0.353-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/ruby-doc?distro=oraclelinux-7.0 | oraclelinux | ruby-doc | < 2.0.0.353-22.el7_0 | oraclelinux-7.0 | ||
Affected | pkg:rpm/oraclelinux/ruby-devel?distro=oraclelinux-7.0 | oraclelinux | ruby-devel | < 2.0.0.353-22.el7_0 | oraclelinux-7.0 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |