Alerts This Week
Warning Icon 1 681
Alerts This Week
Warning Icon 1 681

Mageia 9: MGASA-2024-0160 Moderate: Ruby Buffer Overread and RCE

mageia
Calendar Grey May 9, 2024
Dist Mageia Esm H88
Enhanced Ruby libraries tackle significant security flaws in Mageia, improving protections for StringIO and RDoc to uphold best security standards.
Buffer overread vulnerability in StringIO

Summary

Buffer overread vulnerability in StringIO. (CVE-2024-27280) RCE vulnerability with .rdoc_options in RDoc. (CVE-2024-27281) Arbitrary memory address read vulnerability with Regex search. (CVE-2024-27282)

References

- https://bugs.mageia.org/show_bug.cgi?id=33138

- https://www.ruby-lang.org/en/news/2024/04/23/ruby-3-1-5-released/

- https://www.cve.org/CVERecord?id=CVE-2024-27280

- https://www.cve.org/CVERecord?id=CVE-2024-27281

- https://www.cve.org/CVERecord?id=CVE-2024-27282

Resolution

SRPMS

- 9/core/ruby-3.1.5-45.mga9

Publication date: 09 May 2024
URL: https://advisories.mageia.org/MGASA-2024-0160.html
Type: security
CVE: CVE-2024-27280, CVE-2024-27281, CVE-2024-27282

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here