Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Debian DSA-4031-1 Ruby 2.3 Moderate: Fix Info Disclosure and DoS

debian
Calendar Grey November 11, 2017
Debian Logo
Enhance your ruby2.3 dependencies to address security flaws, encompassing risk of information leaks and service interruption issues.
Several vulnerabilities have been discovered in the interpreter for the Ruby language

Summary

CVE-2017-0898

aerodudrizzt reported a buffer underrun vulnerability in the sprintf
method of the Kernel module resulting in heap memory corruption or
information disclosure from the heap.

CVE-2017-0903

Max Justicz reported that RubyGems is prone to an unsafe object
deserialization vulnerability. When parsed by an application which
processes gems, a specially crafted YAML formatted gem specification
can lead to remote code execution.

CVE-2017-10784

Yusuke Endoh discovered an escape sequence injection vulnerability
in the Basic authentication of WEBrick. An attacker can take
advantage of this flaw to inject malicious escape sequences to the
WEBrick log and potentially execute control characters on the
victim's terminal emulator when reading logs.

CVE-2017-14033

asac reported a buffer underrun vulnerability in the OpenSSL
extension. A remote attacker can take advantage of this flaw to
cause the Ruby interpreter to crash leading to a denial of s...

Read the Full Advisory

Package: ruby2.3
CVE ID: CVE-2017-0898 CVE-2017-0903 CVE-2017-10784 CVE-2017-14033

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here