Alerts This Week
Warning Icon 1 914
Alerts This Week
Warning Icon 1 914

Red Hat Enterprise Linux: RHSA-2022-6447-01 Moderate: Ruby 2.7 Bug Fix

red hat
Calendar Grey September 13, 2022
Dist Redhat Esm H88
Oracle issues bulletin ORCL-2022-4531-02 for Python 3.8, focusing on low-level security concerns and software enhancements.
An update for the ruby:2.7 module is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.
The following packages have been upgraded to a later upstream version: ruby (2.7.6). (BZ#2109424)
Security Fix(es):
* ruby: Regular expression denial of service vulnerability of Date parsing methods (CVE-2021-41817)
* ruby: Cookie prefix spoofing in CGI::Cookie.parse (CVE-2021-41819)
* Ruby: Buffer overrun in String-to-Float conversion (CVE-2022-28739)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

https://access.redhat.com/security/cve/CVE-2021-41817 https://access.redhat.com/security/cve/CVE-2021-41819 https://access.redhat.com/security/cve/CVE-2022-28739 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: ruby-2.7.6-138.module+el8.6.0+16148+54b2ba8f.src.rpm rubygem-abrt-0.4.0-1.module+el8.3.0+7192+4e3a532a.src.rpm rubygem-bson-4.8.1-1.module+el8.3.0+7192+4e3a532a.src.rpm rubygem-mongo-2.11.3-1.module+el8.3.0+7192+4e3a532a.src.rpm rubygem-mysql2-0.5.3-1.module+el8.3.0+7192+4e3a532a.src.rpm rubygem-pg-1.2.3-1.module+el8.3.0+7192+4e3a532a.src.rpm
aarch64: ruby-2.7.6-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm ruby-debuginfo-2.7.6-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm ruby-debugsource-2.7.6-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm ruby-devel-2.7.6-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm ruby-libs-2.7.6-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm ruby-libs-debuginfo-2.7.6-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm rubygem-bigdecimal-2.0.0-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm rubygem-bigdecimal-debuginfo-2.0.0-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm rubygem-bson-4.8.1-1.module+el8.3.0+7192+4e3a532a.aarch64.rpm rubygem-bson-debuginfo-4.8.1-1.module+el8.3.0+7192+4e3a532a.aarch64.rpm rubygem-bson-debugsource-4.8.1-1.module+el8.3.0+7192+4e3a532a.aarch64.rpm rubygem-io-console-0.5.6-138.module+el8.6.0+16148+54b2ba8f.aarch64.rpm

Read the Full Advisory


Advisory ID: RHSA-2022:6447-01
Product: Red Hat Enterprise Linux
Issue date: 2022-09-13

Topic

An update for the ruby:2.7 module is now available for Red Hat EnterpriseLinux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64

Bugs Fixed

2025104 - CVE-2021-41817 ruby: Regular expression denial of service vulnerability of Date parsing methods

2026757 - CVE-2021-41819 ruby: Cookie prefix spoofing in CGI::Cookie.parse

2075687 - CVE-2022-28739 Ruby: Buffer overrun in String-to-Float conversion

2109424 - ruby:2.7/ruby: Rebase to the latest Ruby 2.7 release [rhel-8] [rhel-8.6.0.z]

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here