You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa Ruby

Sigurnosni nedostaci programskog paketa Ruby

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LUB

==========================================================================
Ubuntu Security Notice USN-4201-1
November 26, 2019

ruby2.3, ruby2.5 vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

– Ubuntu 19.10
– Ubuntu 19.04
– Ubuntu 18.04 LTS
– Ubuntu 16.04 LTS

Summary:

Several security issues were fixed in Ruby.

Software Description:
– ruby2.5: Interpreter of object-oriented scripting language Ruby
– ruby2.3: Object-oriented scripting language

Details:

It was discovered that Ruby incorrectly handled certain files.
An attacker could possibly use this issue to pass path matching
what can lead to an unauthorized access. (CVE-2019-15845)

It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could use this issue to cause a denial of service.
(CVE-2019-16201)

It was discovered that Ruby incorrectly handled certain HTTP headers.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-16254)

It was discovered that Ruby incorrectly handled certain inputs.
An attacker could possibly use this issue to execute arbitrary code.
(CVE-2019-16255)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 19.10:
libruby2.5 2.5.5-4ubuntu2.1
ruby2.5 2.5.5-4ubuntu2.1

Ubuntu 19.04:
libruby2.5 2.5.5-1ubuntu1.1
ruby2.5 2.5.5-1ubuntu1.1

Ubuntu 18.04 LTS:
libruby2.5 2.5.1-1ubuntu1.6
ruby2.5 2.5.1-1ubuntu1.6

Ubuntu 16.04 LTS:
libruby2.3 2.3.1-2~ubuntu16.04.14
ruby2.3 2.3.1-2~ubuntu16.04.14

In general, a standard system update will make all the necessary changes.

References:
https://usn.ubuntu.com/4201-1
CVE-2019-15845, CVE-2019-16201, CVE-2019-16254, CVE-2019-16255

Package Information:
https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-4ubuntu2.1
https://launchpad.net/ubuntu/+source/ruby2.5/2.5.5-1ubuntu1.1
https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.6
https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~ubuntu16.04.14
—–BEGIN PGP SIGNATURE—–
Version: GnuPG v1

iQIcBAEBAgAGBQJd3VSUAAoJEEW851uECx9peCMP/RMnJtg/JL5jknRbOM0AksZ4
8bnbyNOXkHc+WOehHJ4NM83B64OvhlD+kX3Y7J0HgjNyVBw4SSqhjhHm4CASpyhV
tXtJjJYjdNt5So2UvxU5kmd8jeul/TqWsDbcV4h+85EYrlQage92UJ/Qit3eisge
g4OkvnPVAwSkrfgeib1x4GF/sOAOhDIXZuuVm67iXGWSKC+41Vcsp4kuYMS2QNji
NP+G9HFrMsb2TiDH95HqfuDJ5nDbp6iK0ivs781s5if8Kmz9e6f7WTmkh0ASyZiu
dc6rpacDvqH13AR6vu8+qNvME+RUXH2pfsM/aj/zF/58ArbcFAPyS81mGr4rXCGg
wn6817bepCDb4qIVg3WOVZRniAo36X80qv5m2HXDHuS+VVSQq69Lj7LVyQebGpWA
qS8RcZm7srdD36NG1pOfElajmCJrYzgIZqCEA2Z4DWj6OF6SlOyifYomwZ+gyE3b
Q+epRj2KEgIkiJv4OiAjAKetAmv9ATmzdNOEk5DztjnASVHV7Smn/QYacwmzqPbM
gYNMENL0ZMIWPl/LvJp4TqBWARqKysWKJDfmrTfBgPg4aYtlZWNtLiiXnKBLVz1x
+8X0uysQMm9ajUyeKIOc2jUbXbB9qvtPe8RFOgTufXrzWJw+6zcdn/BHy6eFHk8F
UL4dEzUQLh7hOFT5/jVp
=Mu0x
—–END PGP SIGNATURE—–

AutorJosip Papratovic
Cert idNCERT-REF-2019-11-0001-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
IzvorAdobe
Top
More in Preporuke
Sigurnosni nedostatak programskog paketa qemu-kvm-ma

Otkriven je sigurnosni nedostatak u programskom paketu qemu-kvm-ma za operacijski sustav RHEL. Otkriveni nedostatak potencijalnim napadačima omogućuje izvršavanje proizvoljnog programskog...

Close