Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Red Hat: RHSA-2022-6451-01 Important: Python 3.9 Security Patch

red hat
Calendar Grey September 13, 2022
Dist Redhat Esm H88
Ubuntu issues a timely security alert concerning Python 3.9 update, rectifying significant vulnerabilities while bolstering overall system integrity.
An update for the ruby:3.0 module is now available for Red Hat Enterprise Linux 8

Solution

For details on how to apply this update, which includes the changes described in this advisory, refer to:

https://access.redhat.com/articles/11258

Summary

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.
The following packages have been upgraded to a later upstream version: ruby (3.0.4). (BZ#2109431)
Security Fix(es):
* ruby: Regular expression denial of service vulnerability of Date parsing methods (CVE-2021-41817)
* ruby: Cookie prefix spoofing in CGI::Cookie.parse (CVE-2021-41819)
* Ruby: Double free in Regexp compilation (CVE-2022-28738)
* Ruby: Buffer overrun in String-to-Float conversion (CVE-2022-28739)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Bug Fix(es):
* ruby 3.0: User-installed rubygems plugins are not being loaded [RHEL8] (BZ#2110981)

References

https://access.redhat.com/security/cve/CVE-2021-41817 https://access.redhat.com/security/cve/CVE-2021-41819 https://access.redhat.com/security/cve/CVE-2022-28738 https://access.redhat.com/security/cve/CVE-2022-28739 https://access.redhat.com/security/updates/classification/#moderate

Package List

Red Hat Enterprise Linux AppStream (v. 8):
Source: ruby-3.0.4-141.module+el8.6.0+16311+3e5e17e9.src.rpm rubygem-abrt-0.4.0-1.module+el8.5.0+11580+845038eb.src.rpm rubygem-mysql2-0.5.3-1.module+el8.5.0+11580+845038eb.src.rpm rubygem-pg-1.2.3-1.module+el8.5.0+11580+845038eb.src.rpm
aarch64: ruby-3.0.4-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm ruby-debuginfo-3.0.4-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm ruby-debugsource-3.0.4-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm ruby-devel-3.0.4-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm ruby-libs-3.0.4-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm ruby-libs-debuginfo-3.0.4-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm rubygem-bigdecimal-3.0.0-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm rubygem-bigdecimal-debuginfo-3.0.0-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm rubygem-io-console-0.5.7-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm rubygem-io-console-debuginfo-0.5.7-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm rubygem-json-2.5.1-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm rubygem-json-debuginfo-2.5.1-141.module+el8.6.0+16311+3e5e17e9.aarch64.rpm rubygem-mysql2-0.5.3-1.module+el8.5.0+11580+845038eb.aarch64.rpm rubygem-mysql2-debuginfo-0.5.3-1.module+el8.5.0+11580+845038eb.aarch64.rpm

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Advisory ID: RHSA-2022:6450-01
Product: Red Hat Enterprise Linux
Issue date: 2022-09-13

Topic

An update for the ruby:3.0 module is now available for Red Hat EnterpriseLinux 8.Red Hat Product Security has rated this update as having a security impactof Moderate. A Common Vulnerability Scoring System (CVSS) base score, whichgives a detailed severity rating, is available for each vulnerability fromthe CVE link(s) in the References section.

Relevant Releases Architectures

Red Hat Enterprise Linux AppStream (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64

Bugs Fixed

2025104 - CVE-2021-41817 ruby: Regular expression denial of service vulnerability of Date parsing methods

2026757 - CVE-2021-41819 ruby: Cookie prefix spoofing in CGI::Cookie.parse

2075685 - CVE-2022-28738 Ruby: Double free in Regexp compilation

2075687 - CVE-2022-28739 Ruby: Buffer overrun in String-to-Float conversion

2109431 - ruby:3.0/ruby: Rebase to the latest Ruby 3.0 release [rhel-8] [rhel-8.6.0.z]

2110981 - ruby 3.0: User-installed rubygems plugins are not being loaded [RHEL8] [rhel-8.6.0.z]

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here