Alerts This Week
Warning Icon 1 640
Alerts This Week
Warning Icon 1 640

Ubuntu 20.04 LTS USN-4922-1 Moderate: Ruby XML Parsing Vulnerability

ubuntu
Calendar Grey April 20, 2021
Dist Ubuntu Esm H88
Upgrade your Ubuntu machine to resolve significant Ruby XML parsing vulnerabilities highlighted in USN-4922-1.
Ruby incorrectly handled XML documents.

Summary

Ruby incorrectly handled XML documents.

Software Description:

- ruby2.7: Object-oriented scripting language

- ruby2.5: Object-oriented scripting language

- ruby2.3: Object-oriented scripting language

Details:

Juho Nurminen discovered that the REXML gem bundled with Ruby incorrectly

parsed and serialized XML documents. A remote attacker could possibly use

this issue to perform an XML round-trip attack.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.10:
  libruby2.7                      2.7.1-3ubuntu1.3
  ruby2.7                         2.7.1-3ubuntu1.3

Ubuntu 20.04 LTS:
  libruby2.7                      2.7.0-5ubuntu1.4
  ruby2.7                         2.7.0-5ubuntu1.4

Ubuntu 18.04 LTS:
  libruby2.5                      2.5.1-1ubuntu1.9
  ruby2.5                         2.5.1-1ubuntu1.9

Ubuntu 16.04 LTS:
  libruby2.3                      2.3.1-2~ubuntu16.04.16
  ruby2.3                         2.3.1-2~ubuntu16.04.16

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4922-1

CVE-2021-28965

Severity
important
Lowest
Low
Medium
High
Critical

April 20, 2021

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here