Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Mageia: 2020-0243 Moderate: ruby-RubyGems Symlink Vulnerability

mageia
Calendar Grey June 10, 2020
Dist Mageia Esm H88
Recent updates to the Ruby and RubyGems libraries have addressed several security vulnerabilities in Mageia as of June 10, 2020.
Updated ruby-RubyGems package fixes security vulnerabilities The following vulnerabilities have been reported

Summary

Updated ruby-RubyGems package fixes security vulnerabilities
The following vulnerabilities have been reported.
CVE-2019-8320: Delete directory using symlink when decompressing tar CVE-2019-8321: Escape sequence injection vulnerability in verbose CVE-2019-8322: Escape sequence injection vulnerability in gem owner CVE-2019-8323: Escape sequence injection vulnerability in API response handling CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution CVE-2019-8325: Escape sequence injection vulnerability in errors

References

- https://bugs.mageia.org/show_bug.cgi?id=22696

- https://www.ruby-lang.org/en/news/2019/03/05/multiple-vulnerabilities-in-rubygems/

- https://www.cve.org/CVERecord?id=CVE-2019-XXXX

- https://www.cve.org/CVERecord?id=CVE-2018-1000073

- https://www.cve.org/CVERecord?id=CVE-2018-1000074

- https://www.cve.org/CVERecord?id=CVE-2018-1000075

- https://www.cve.org/CVERecord?id=CVE-2018-1000076

- https://www.cve.org/CVERecord?id=CVE-2018-1000077

- https://www.cve.org/CVERecord?id=CVE-2018-1000078

- https://www.cve.org/CVERecord?id=CVE-2018-1000079

- https://www.cve.org/CVERecord?id=CVE-2019-8320

- https://www.cve.org/CVERecord?id=CVE-2019-8321

- https://www.cve.org/CVERecord?id=CVE-2019-8322

- https://www.cve.org/CVERecord?id=CVE-2019-8323

- https://www.cve.org/CVERecord?id=CVE-2019-8324

- https://www.cve.org/CVERecord?id=CVE-2019-8325

Resolution

SRPMS

- 7/core/ruby-RubyGems-2.6.14-3.1.mga7

Publication date: 10 Jun 2020
URL: https://advisories.mageia.org/MGASA-2020-0243.html
Type: security
CVE: CVE-2019-XXXX, CVE-2018-1000073, CVE-2018-1000074, CVE-2018-1000075, CVE-2018-1000076, CVE-2018-1000077, CVE-2018-1000078, CVE-2018-1000079, CVE-2019-8320, CVE-2019-8321, CVE-2019-8322, CVE-2019-8323, CVE-2019-8324, CVE-2019-8325

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here