Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian: DSA-4721-1 Moderate: ruby2.5 Object Creation and Data Exposure

debian
Calendar Grey July 8, 2020
Debian Logo
Debian Security Advisory DSA-4722-1 outlines vulnerabilities in Python 3.6, highlighting memory corruption and potential information leaks.
Several vulnerabilities have been discovered in the interpreter for the Ruby language

Summary

CVE-2020-10663

Jeremy Evans reported an unsafe object creation vulnerability in the
json gem bundled with Ruby. When parsing certain JSON documents, the
json gem can be coerced into creating arbitrary objects in the
target system.

CVE-2020-10933

Samuel Williams reported a flaw in the socket library which may lead
to exposure of possibly sensitive data from the interpreter.

For the stable distribution (buster), these problems have been fixed in
version 2.5.5-3+deb10u2.

We recommend that you upgrade your ruby2.5 packages.

For the detailed security status of ruby2.5 please refer to its security
tracker page at:


Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: ruby2.5
CVE ID: CVE-2020-10663 CVE-2020-10933

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here