For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to perform system management tasks.
Security Fix(es):
* rubygem-bundler: Dependencies of gems with explicit source may be
installed from a different source (CVE-2020-36327)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2020-36327 https://access.redhat.com/security/updates/classification/#important https://access.redhat.com/articles/6206172
Red Hat Enterprise Linux AppStream E4S (v. 8.1):
Source:
ruby-2.5.5-105.module+el8.1.0+3656+f80bfa1d.src.rpm
rubygem-abrt-0.3.0-4.module+el8.1.0+3656+f80bfa1d.src.rpm
rubygem-bson-4.3.0-2.module+el8.1.0+3656+f80bfa1d.src.rpm
rubygem-bundler-1.16.1-4.module+el8.1.0+14085+cd0ba992.src.rpm
rubygem-mongo-2.5.1-2.module+el8.1.0+3656+f80bfa1d.src.rpm
rubygem-mysql2-0.4.10-4.module+el8.1.0+3656+f80bfa1d.src.rpm
rubygem-pg-1.0.0-2.module+el8.1.0+3656+f80bfa1d.src.rpm
aarch64:
ruby-2.5.5-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
ruby-debuginfo-2.5.5-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
ruby-debugsource-2.5.5-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
ruby-devel-2.5.5-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
ruby-libs-2.5.5-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
ruby-libs-debuginfo-2.5.5-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
rubygem-bigdecimal-1.3.4-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
rubygem-bigdecimal-debuginfo-1.3.4-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
rubygem-bson-4.3.0-2.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
rubygem-bson-debuginfo-4.3.0-2.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
rubygem-bson-debugsource-4.3.0-2.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
rubygem-io-console-0.4.6-105.module+el8.1.0+3656+f80bfa1d.aarch64.rpm
Read the Full Advisory
An update for the ruby:2.5 module is now available for Red Hat EnterpriseLinux 8.1 Update Services for SAP Solutions.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Enterprise Linux AppStream E4S (v. 8.1) - aarch64, noarch, ppc64le, s390x, x86_64
1958999 - CVE-2020-36327 rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source
Get the latest Linux and open source security news straight to your inbox.