Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Mageia: 2021-0125 Moderate: Ruby Nokogiri XML Parsing Vulnerability

mageia
Calendar Grey March 11, 2021
Dist Mageia Esm H88
Recent updates to the ruby-mechanize library have resolved a critical command injection vulnerability to boost platform safety. Release date: 15 Mar 2021.
In Mechanize, from v2.0.0 until v2.7.7, there is a command injection vulnerability

Summary

In Mechanize, from v2.0.0 until v2.7.7, there is a command injection vulnerability. Affected versions of Mechanize allow for OS commands to be injected using several classes' methods which implicitly use Ruby's Kernel#open method (CVE-2021-21289).

References

- https://bugs.mageia.org/show_bug.cgi?id=28448

- https://lists.debian.org/debian-lts-announce/2021/02/msg00021.html

- https://www.cve.org/CVERecord?id=CVE-2021-21289

Resolution

SRPMS

- 7/core/ruby-mechanize-2.7.6-2.1.mga7

- 8/core/ruby-mechanize-2.7.6-3.1.mga8

Publication date: 12 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0124.html
Type: security
CVE: CVE-2021-21289

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here