Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 501
Alerts This Week
Warning Icon 1 501

openSUSE Leap 15.0: 2018:2124-1 Moderate: Rubygem-Sprockets Path Issue

opensuse
Calendar Grey July 28, 2018
Scroller Opensuse
openSUSE releases critical update for rubygem-sprockets tackling CVE-2018-3760. Users urged to apply patch without delay.
An update that fixes one vulnerability is now available.

Description

This update for rubygem-sprockets fixes the following issues:

The following security vulnerability was addressed:

- CVE-2018-3760: Fixed a path traversal issue in

sprockets/server.rb:forbidden_request?(), which allowed remote attackers to read arbitrary files (bsc#1098369)

This update was imported from the SUSE:SLE-15:Update update project.

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-773=1

Package List

- openSUSE Leap 15.0 (x86_64):

ruby2.5-rubygem-sprockets-3.7.2-lp150.2.3.1

ruby2.5-rubygem-sprockets-doc-3.7.2-lp150.2.3.1

References

https://www.suse.com/security/cve/CVE-2018-3760.html

https://bugzilla.suse.com/1098369

--

Announcement ID: openSUSE-SU-2018:2124-1
Rating: moderate
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.