[RLSA-2022:5779] ruby:2.5 security update

Severity Moderate
Affected Packages 43
CVEs 2

An update is available for rubygem-bson, rubygem-mysql2, rubygem-bundler, ruby, rubygem-mongo, rubygem-pg, rubygem-abrt. This update affects Rocky Linux 8. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE list

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.

Security Fix(es):

  • ruby: Regular expression denial of service vulnerability of Date parsing methods (CVE-2021-41817)

  • ruby: Cookie prefix spoofing in CGI::Cookie.parse (CVE-2021-41819)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Package Affected Version
pkg:rpm/rockylinux/rubygems?arch=noarch&distro=rockylinux-8.6 < 2.7.6.3-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygems-devel?arch=noarch&distro=rockylinux-8.6 < 2.7.6.3-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-xmlrpc?arch=noarch&distro=rockylinux-8.6 < 0.3.0-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-test-unit?arch=noarch&distro=rockylinux-8.6 < 3.2.7-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-rdoc?arch=noarch&distro=rockylinux-8.6 < 6.0.1.1-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-rake?arch=noarch&distro=rockylinux-8.6 < 12.3.3-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-psych?arch=x86_64&distro=rockylinux-8.6 < 3.0.2-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-psych?arch=aarch64&distro=rockylinux-8.6 < 3.0.2-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-power_assert?arch=noarch&distro=rockylinux-8.6 < 1.1.1-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-pg?arch=x86_64&distro=rockylinux-8.4 < 1.0.0-2.module+el8.4.0+592+03ff458a
pkg:rpm/rockylinux/rubygem-pg?arch=aarch64&distro=rockylinux-8.4 < 1.0.0-2.module+el8.4.0+592+03ff458a
pkg:rpm/rockylinux/rubygem-pg-doc?arch=noarch&distro=rockylinux-8.4 < 1.0.0-2.module+el8.4.0+592+03ff458a
pkg:rpm/rockylinux/rubygem-openssl?arch=x86_64&distro=rockylinux-8.6 < 2.1.2-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-openssl?arch=aarch64&distro=rockylinux-8.6 < 2.1.2-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-net-telnet?arch=noarch&distro=rockylinux-8.6 < 0.1.1-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-mysql2?arch=x86_64&distro=rockylinux-8.5 < 0.4.10-4.module+el8.5.0+739+43897a5e
pkg:rpm/rockylinux/rubygem-mysql2?arch=aarch64&distro=rockylinux-8.5 < 0.4.10-4.module+el8.5.0+739+43897a5e
pkg:rpm/rockylinux/rubygem-mysql2-doc?arch=noarch&distro=rockylinux-8.5 < 0.4.10-4.module+el8.5.0+739+43897a5e
pkg:rpm/rockylinux/rubygem-mongo?arch=noarch&distro=rockylinux-8.4 < 2.5.1-2.module+el8.4.0+592+03ff458a
pkg:rpm/rockylinux/rubygem-mongo-doc?arch=noarch&distro=rockylinux-8.4 < 2.5.1-2.module+el8.4.0+592+03ff458a
pkg:rpm/rockylinux/rubygem-minitest?arch=noarch&distro=rockylinux-8.6 < 5.10.3-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-json?arch=x86_64&distro=rockylinux-8.6 < 2.1.0-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-json?arch=aarch64&distro=rockylinux-8.6 < 2.1.0-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-io-console?arch=x86_64&distro=rockylinux-8.6 < 0.4.6-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-io-console?arch=aarch64&distro=rockylinux-8.6 < 0.4.6-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-did_you_mean?arch=noarch&distro=rockylinux-8.6 < 1.2.0-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-bundler?arch=noarch&distro=rockylinux-8.6 < 1.16.1-4.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-bundler-doc?arch=noarch&distro=rockylinux-8.6 < 1.16.1-4.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-bson?arch=x86_64&distro=rockylinux-8.4 < 4.3.0-2.module+el8.4.0+592+03ff458a
pkg:rpm/rockylinux/rubygem-bson?arch=aarch64&distro=rockylinux-8.4 < 4.3.0-2.module+el8.4.0+592+03ff458a
pkg:rpm/rockylinux/rubygem-bson-doc?arch=noarch&distro=rockylinux-8.4 < 4.3.0-2.module+el8.4.0+592+03ff458a
pkg:rpm/rockylinux/rubygem-bigdecimal?arch=x86_64&distro=rockylinux-8.6 < 1.3.4-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-bigdecimal?arch=aarch64&distro=rockylinux-8.6 < 1.3.4-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/rubygem-abrt?arch=noarch&distro=rockylinux-8.5 < 0.3.0-4.module+el8.5.0+738+032c9c02
pkg:rpm/rockylinux/rubygem-abrt-doc?arch=noarch&distro=rockylinux-8.5 < 0.3.0-4.module+el8.5.0+738+032c9c02
pkg:rpm/rockylinux/ruby?arch=x86_64&distro=rockylinux-8.6 < 2.5.9-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/ruby?arch=aarch64&distro=rockylinux-8.6 < 2.5.9-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/ruby-libs?arch=x86_64&distro=rockylinux-8.6 < 2.5.9-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/ruby-libs?arch=aarch64&distro=rockylinux-8.6 < 2.5.9-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/ruby-irb?arch=noarch&distro=rockylinux-8.6 < 2.5.9-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/ruby-doc?arch=noarch&distro=rockylinux-8.6 < 2.5.9-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/ruby-devel?arch=x86_64&distro=rockylinux-8.6 < 2.5.9-110.module+el8.6.0+992+fc951c18
pkg:rpm/rockylinux/ruby-devel?arch=aarch64&distro=rockylinux-8.6 < 2.5.9-110.module+el8.6.0+992+fc951c18
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/rockylinux/rubygems?arch=noarch&distro=rockylinux-8.6 rockylinux rubygems < 2.7.6.3-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygems-devel?arch=noarch&distro=rockylinux-8.6 rockylinux rubygems-devel < 2.7.6.3-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-xmlrpc?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-xmlrpc < 0.3.0-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-test-unit?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-test-unit < 3.2.7-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-rdoc?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-rdoc < 6.0.1.1-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-rake?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-rake < 12.3.3-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-psych?arch=x86_64&distro=rockylinux-8.6 rockylinux rubygem-psych < 3.0.2-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 x86_64
Affected pkg:rpm/rockylinux/rubygem-psych?arch=aarch64&distro=rockylinux-8.6 rockylinux rubygem-psych < 3.0.2-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 aarch64
Affected pkg:rpm/rockylinux/rubygem-power_assert?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-power_assert < 1.1.1-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-pg?arch=x86_64&distro=rockylinux-8.4 rockylinux rubygem-pg < 1.0.0-2.module+el8.4.0+592+03ff458a rockylinux-8.4 x86_64
Affected pkg:rpm/rockylinux/rubygem-pg?arch=aarch64&distro=rockylinux-8.4 rockylinux rubygem-pg < 1.0.0-2.module+el8.4.0+592+03ff458a rockylinux-8.4 aarch64
Affected pkg:rpm/rockylinux/rubygem-pg-doc?arch=noarch&distro=rockylinux-8.4 rockylinux rubygem-pg-doc < 1.0.0-2.module+el8.4.0+592+03ff458a rockylinux-8.4 noarch
Affected pkg:rpm/rockylinux/rubygem-openssl?arch=x86_64&distro=rockylinux-8.6 rockylinux rubygem-openssl < 2.1.2-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 x86_64
Affected pkg:rpm/rockylinux/rubygem-openssl?arch=aarch64&distro=rockylinux-8.6 rockylinux rubygem-openssl < 2.1.2-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 aarch64
Affected pkg:rpm/rockylinux/rubygem-net-telnet?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-net-telnet < 0.1.1-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-mysql2?arch=x86_64&distro=rockylinux-8.5 rockylinux rubygem-mysql2 < 0.4.10-4.module+el8.5.0+739+43897a5e rockylinux-8.5 x86_64
Affected pkg:rpm/rockylinux/rubygem-mysql2?arch=aarch64&distro=rockylinux-8.5 rockylinux rubygem-mysql2 < 0.4.10-4.module+el8.5.0+739+43897a5e rockylinux-8.5 aarch64
Affected pkg:rpm/rockylinux/rubygem-mysql2-doc?arch=noarch&distro=rockylinux-8.5 rockylinux rubygem-mysql2-doc < 0.4.10-4.module+el8.5.0+739+43897a5e rockylinux-8.5 noarch
Affected pkg:rpm/rockylinux/rubygem-mongo?arch=noarch&distro=rockylinux-8.4 rockylinux rubygem-mongo < 2.5.1-2.module+el8.4.0+592+03ff458a rockylinux-8.4 noarch
Affected pkg:rpm/rockylinux/rubygem-mongo-doc?arch=noarch&distro=rockylinux-8.4 rockylinux rubygem-mongo-doc < 2.5.1-2.module+el8.4.0+592+03ff458a rockylinux-8.4 noarch
Affected pkg:rpm/rockylinux/rubygem-minitest?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-minitest < 5.10.3-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-json?arch=x86_64&distro=rockylinux-8.6 rockylinux rubygem-json < 2.1.0-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 x86_64
Affected pkg:rpm/rockylinux/rubygem-json?arch=aarch64&distro=rockylinux-8.6 rockylinux rubygem-json < 2.1.0-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 aarch64
Affected pkg:rpm/rockylinux/rubygem-io-console?arch=x86_64&distro=rockylinux-8.6 rockylinux rubygem-io-console < 0.4.6-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 x86_64
Affected pkg:rpm/rockylinux/rubygem-io-console?arch=aarch64&distro=rockylinux-8.6 rockylinux rubygem-io-console < 0.4.6-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 aarch64
Affected pkg:rpm/rockylinux/rubygem-did_you_mean?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-did_you_mean < 1.2.0-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-bundler?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-bundler < 1.16.1-4.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-bundler-doc?arch=noarch&distro=rockylinux-8.6 rockylinux rubygem-bundler-doc < 1.16.1-4.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/rubygem-bson?arch=x86_64&distro=rockylinux-8.4 rockylinux rubygem-bson < 4.3.0-2.module+el8.4.0+592+03ff458a rockylinux-8.4 x86_64
Affected pkg:rpm/rockylinux/rubygem-bson?arch=aarch64&distro=rockylinux-8.4 rockylinux rubygem-bson < 4.3.0-2.module+el8.4.0+592+03ff458a rockylinux-8.4 aarch64
Affected pkg:rpm/rockylinux/rubygem-bson-doc?arch=noarch&distro=rockylinux-8.4 rockylinux rubygem-bson-doc < 4.3.0-2.module+el8.4.0+592+03ff458a rockylinux-8.4 noarch
Affected pkg:rpm/rockylinux/rubygem-bigdecimal?arch=x86_64&distro=rockylinux-8.6 rockylinux rubygem-bigdecimal < 1.3.4-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 x86_64
Affected pkg:rpm/rockylinux/rubygem-bigdecimal?arch=aarch64&distro=rockylinux-8.6 rockylinux rubygem-bigdecimal < 1.3.4-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 aarch64
Affected pkg:rpm/rockylinux/rubygem-abrt?arch=noarch&distro=rockylinux-8.5 rockylinux rubygem-abrt < 0.3.0-4.module+el8.5.0+738+032c9c02 rockylinux-8.5 noarch
Affected pkg:rpm/rockylinux/rubygem-abrt-doc?arch=noarch&distro=rockylinux-8.5 rockylinux rubygem-abrt-doc < 0.3.0-4.module+el8.5.0+738+032c9c02 rockylinux-8.5 noarch
Affected pkg:rpm/rockylinux/ruby?arch=x86_64&distro=rockylinux-8.6 rockylinux ruby < 2.5.9-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 x86_64
Affected pkg:rpm/rockylinux/ruby?arch=aarch64&distro=rockylinux-8.6 rockylinux ruby < 2.5.9-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 aarch64
Affected pkg:rpm/rockylinux/ruby-libs?arch=x86_64&distro=rockylinux-8.6 rockylinux ruby-libs < 2.5.9-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 x86_64
Affected pkg:rpm/rockylinux/ruby-libs?arch=aarch64&distro=rockylinux-8.6 rockylinux ruby-libs < 2.5.9-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 aarch64
Affected pkg:rpm/rockylinux/ruby-irb?arch=noarch&distro=rockylinux-8.6 rockylinux ruby-irb < 2.5.9-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/ruby-doc?arch=noarch&distro=rockylinux-8.6 rockylinux ruby-doc < 2.5.9-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 noarch
Affected pkg:rpm/rockylinux/ruby-devel?arch=x86_64&distro=rockylinux-8.6 rockylinux ruby-devel < 2.5.9-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 x86_64
Affected pkg:rpm/rockylinux/ruby-devel?arch=aarch64&distro=rockylinux-8.6 rockylinux ruby-devel < 2.5.9-110.module+el8.6.0+992+fc951c18 rockylinux-8.6 aarch64
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...