Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Slackware: 2017-353-01 Critical: Ruby Command Execution Issue

slackware
Calendar Grey December 20, 2017
Dist Slackware Esm H88
Recent updates introduce ruby modules for Slackware, tackling a crucial code execution vulnerability, thereby enhancing system security.
New ruby packages are available for Slackware 14.2 and -current to fix a security issue

Summary

Here are the details from the Slackware 14.2 ChangeLog: patches/packages/ruby-2.2.9-i586-1_slack14.2.txz: Upgraded. This update fixes a security issue: Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and puttextfile use Kernel#open to open a local file. If the localfile argument starts with the pipe character "|", the command following the pipe character is executed. The default value of localfile is File.basename(remotefile), so malicious FTP servers could cause arbitrary command execution. For more information, see: https://www.cve.org/CVERecord?id=CVE-2017-17405 (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 14.2:
Updated package for Slackware x86_64 14.2:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 14.2 package: 095fdfa07170e4697d42fe43f3030b81 ruby-2.2.9-i586-1_slack14.2.txz
Slackware x86_64 14.2 package: e124e967447b3565b0f9baa6e56bdd6b ruby-2.2.9-x86_64-1_slack14.2.txz
Slackware -current package: f27cc750ef8b400998caf6cde04dc0c0 d/ruby-2.4.3-i586-1.txz
Slackware x86_64 -current package: d7da38ad9540e469e6fb5710ed5a8b54 d/ruby-2.4.3-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg ruby-2.2.9-i586-1_slack14.2.txz

Related News

Your message here