Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Debian 11 Bullseye DLA-3858-1 Critical: Ruby Remote Code Execution

debian lts
Calendar Grey September 2, 2024
Dist Debian Esm H88
Several security flaws discovered in the Ruby runtime environment result in denial of service, potential data exposure, and threats of remote code execution.
Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in denial-of-service (DoS), information leak, and remote code execution

Summary

CVE-2021-33621

The cgi gem allows HTTP response splitting. This is relevant to
applications that use untrusted user input either to generate an
HTTP response or to create a CGI::Cookie object.

CVE-2022-28739

Buffer over-read occurs in String-to-Float conversion, including
Kernel#Float and String#to_f.

CVE-2023-28755

A ReDoS issue was discovered in the URI component. The URI parser
mishandles invalid URLs that have specific characters. It causes
an increase in execution time for parsing strings to URI objects.

CVE-2023-28756

A ReDoS issue was discovered in the Time component. The Time
parser mishandles invalid URLs that have specific characters. It
causes an increase in execution time for parsing strings to Time
objects.

CVE-2023-36617

Follow-up fix for CVE-2023-28755.

CVE-2024-27280

A buffer-overread issue was discovered in StringIO. The ungetbyte
and ungetc methods on a StringIO can read past the end of a

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

Package: ruby2.7
Version: 2.7.4-1+deb11u2
CVE ID: CVE-2021-33621 CVE-2022-28739 CVE-2023-28755 CVE-2023-28756
Debian Bug: 1009957 1024799 1038408 1067802 1069966 1069968

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here