[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

RHSA-2022:6855-01 -- Redhat rh-ruby30-ruby

ID: oval:org.secpod.oval:def:507194Date: (C)2022-10-20   (M)2024-04-17
Class: PATCHFamily: unix




Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. The following packages have been upgraded to a later upstream version: rh-ruby30-ruby . Security Fix: * ruby: buffer overflow in CGI.escape_html * ruby: Regular expression denial of service vulnerability of Date parsing methods * ruby: Cookie prefix spoofing in CGI::Cookie.parse * Ruby: Double free in Regexp compilation * Ruby: Buffer overrun in String-to-Float conversion For more details about the security issue, including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page listed in the References section. Bug Fix: * rh-ruby30 ruby: User-installed rubygems plugins are not being loaded

Platform:
Red Hat Enterprise Linux 7
Product:
rh-ruby30-ruby
Reference:
RHSA-2022:6855-01
CVE-2021-41816
CVE-2021-41817
CVE-2021-41819
CVE-2022-28738
CVE-2022-28739
CVE    5
CVE-2021-41816
CVE-2021-41819
CVE-2021-41817
CVE-2022-28738
...

© SecPod Technologies