Alerts This Week
Warning Icon 1 684
Alerts This Week
Warning Icon 1 684

Fedora 26: 2018-1fffa787e7 Critical: RubyGems Multiple Issues

fedora
Calendar Grey March 11, 2018
Dist Fedora Esm H88
Critical vulnerabilities in RubyGems rectified by Fedora on 2018-03-11. Safeguard your environment against possible risks!
Fix: Multiple vulnerabilities in RubyGems https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/

Summary

Ruby is the interpreted scripting language for quick and easy

object-oriented programming. It has many features to process text

files and to do system management tasks (as in Perl). It is simple,

straight-forward, and extensible.

Fix: Multiple vulnerabilities in RubyGems https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/

[ 1 ] Bug #1547431 - CVE-2018-1000073 CVE-2018-1000074 CVE-2018-1000075 CVE-2018-1000076 CVE-2018-1000077 CVE-2018-1000078 CVE-2018-1000079 rubygems: various flaws [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1547431

[ 2 ] Bug #1528226 - CVE-2017-17790 ruby: Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code execution [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1528226

su -c 'dnf upgrade ruby' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 26
Version: 2.4.3
Release: 87.fc26
Summary: An interpreter of object-oriented scripting language

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here