Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Mageia 7: 2020-0121 Critical: Ruby-Rake OS Command Injection

mageia
Calendar Grey March 6, 2020
Dist Mageia Esm H88
Recent updates to the ruby-rake libraries resolve a critical OS command execution vulnerability found in Mageia, bolstering security across the platform.
Updated ruby-rake package fixes security vulnerability: There is an OS command injection vulnerability in Rake < 12.3.3 in Rake::FileList when supplying a filename that begins wit...

Summary

Updated ruby-rake package fixes security vulnerability:
There is an OS command injection vulnerability in Rake < 12.3.3 in Rake::FileList when supplying a filename that begins with the pipe character (CVE-2020-8130).

References

- https://bugs.mageia.org/show_bug.cgi?id=26266

- https://lists.debian.org/debian-lts-announce/2020/02/msg00026.html

- https://www.cve.org/CVERecord?id=CVE-2020-8130

Resolution

SRPMS

- 7/core/ruby-rake-12.3.0-21.mga7

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Mar 2020
URL: https://advisories.mageia.org/MGASA-2020-0121.html
Type: security
CVE: CVE-2020-8130

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here