Updated ruby-json packages fix security vulnerability: In ruby-json before 2.3.0, there is an unsafe object creation vulnerability. When parsing certain JSON documents, the json gem can be coerced into creating arbitrary objects in the target system (CVE-2020-10663). . MGASA-2020-0186 - Updated ruby-json packages fix security vulnerability Publication date: 05 May 2020 URL: https://advisories.mageia.org/MGASA-2020-0186.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-10663 Updated ruby-json packages fix security vulnerability: In ruby-json before 2.3.0, there is an unsafe object creation vulnerability. When parsing certain JSON documents, the json gem can be coerced into creating arbitrary objects in the target system (CVE-2020-10663). References: - https://bugs.mageia.org/show_bug.cgi?id=26408 - https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/ - https://lists.debian.org/debian-lts-announce/2020/04/msg00023.html - https://www.cve.org/CVERecord?id=CVE-2020-10663 SRPMS: - 7/core/ruby-json-2.1.0-3.1.mga7 . The security notice MGASA-2020-0186 from Mageia targets vulnerabilities found in ruby-json, reinforcing the overall security of the system.. ruby-json security, Mageia update, json vulnerability, safety patch, security fix. . Severity: Important. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.