[ELSA-2014-1912] ruby security update

Severity Moderate
Affected Packages 15
CVEs 3

[2.0.0.353-22]
- Fix REXML billion laughs attack via parameter entity expansion
(CVE-2014-8080).
Resolves: rhbz#1163998
- REXML incomplete fix for CVE-2014-8080 (CVE-2014-8090).
Resolves: rhbz#1163998

[2.0.0.353-21]
- Fix off-by-one stack-based buffer overflow in the encodes() function
(CVE-2014-4975)
Resolves: rhbz#1163998

[2.0.0.353-21]
- Fix FTBFS with new tzdata
Related: rhbz#1163998

ID
ELSA-2014-1912
Severity
moderate
URL
https://linux.oracle.com/errata/ELSA-2014-1912.html
Published
2014-11-26T00:00:00
(9 years ago)
Modified
2014-11-26T00:00:00
(9 years ago)
Rights
Copyright 2014 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/rubygems?distro=oraclelinux-7.0 oraclelinux rubygems < 2.0.14-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/rubygems-devel?distro=oraclelinux-7.0 oraclelinux rubygems-devel < 2.0.14-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/rubygem-rdoc?distro=oraclelinux-7.0 oraclelinux rubygem-rdoc < 4.0.0-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/rubygem-rake?distro=oraclelinux-7.0 oraclelinux rubygem-rake < 0.9.6-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/rubygem-psych?distro=oraclelinux-7.0 oraclelinux rubygem-psych < 2.0.0-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/rubygem-minitest?distro=oraclelinux-7.0 oraclelinux rubygem-minitest < 4.3.2-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/rubygem-json?distro=oraclelinux-7.0 oraclelinux rubygem-json < 1.7.7-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/rubygem-io-console?distro=oraclelinux-7.0 oraclelinux rubygem-io-console < 0.4.2-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/rubygem-bigdecimal?distro=oraclelinux-7.0 oraclelinux rubygem-bigdecimal < 1.2.0-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/ruby?distro=oraclelinux-7.0 oraclelinux ruby < 2.0.0.353-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/ruby-tcltk?distro=oraclelinux-7.0 oraclelinux ruby-tcltk < 2.0.0.353-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/ruby-libs?distro=oraclelinux-7.0 oraclelinux ruby-libs < 2.0.0.353-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/ruby-irb?distro=oraclelinux-7.0 oraclelinux ruby-irb < 2.0.0.353-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/ruby-doc?distro=oraclelinux-7.0 oraclelinux ruby-doc < 2.0.0.353-22.el7_0 oraclelinux-7.0
Affected pkg:rpm/oraclelinux/ruby-devel?distro=oraclelinux-7.0 oraclelinux ruby-devel < 2.0.0.353-22.el7_0 oraclelinux-7.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...