Debian: DSA-4259-1: ruby2.3 security update
Summary
Several vulnerabilities have been discovered in the interpreter for the
Ruby language, which may result in incorrect processing of HTTP/FTP,
directory traversal, command injection, unintended socket creation or
information disclosure.
This update also fixes several issues in RubyGems which could allow an
attacker to use specially crafted gem files to mount cross-site scripting
attacks, cause denial of service through an infinite loop, write arbitrary
files, or run malicious code.
For the stable distribution (stretch), these problems have been fixed in
version 2.3.3-1+deb9u3.
We recommend that you upgrade your ruby2.3 packages.
For the detailed security status of ruby2.3 please refer to
its security tracker page at:
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org