Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian 9 DSA-4259-1 Critical: Ruby2.3 Command Injection Risk

debian
Calendar Grey July 31, 2018
Debian Logo
Uncover vital security patch for Debian's ruby2.5 addressing several vulnerabilities impacting data management.
Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in incorrect processing of HTTP/FTP, directory traversal, command injection,...

Summary

Several vulnerabilities have been discovered in the interpreter for the
Ruby language, which may result in incorrect processing of HTTP/FTP,
directory traversal, command injection, unintended socket creation or
information disclosure.

This update also fixes several issues in RubyGems which could allow an
attacker to use specially crafted gem files to mount cross-site scripting
attacks, cause denial of service through an infinite loop, write arbitrary
files, or run malicious code.

For the stable distribution (stretch), these problems have been fixed in
version 2.3.3-1+deb9u3.

We recommend that you upgrade your ruby2.3 packages.

For the detailed security status of ruby2.3 please refer to
its security tracker page at:

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: ruby2.3
CVE ID: CVE-2017-17405 CVE-2017-17742 CVE-2017-17790 CVE-2018-6914

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here