Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 513
Alerts This Week
Warning Icon 1 513

Stay Secure with the Latest Linux Advisories

Filter%20icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
202

openSUSE Leap 15.6: Python-maturin Low Escape Injection Flaw 2025:03082-1

An update that solves one vulnerability can now be installed.. # Security update for python-maturin Announcement ID: SUSE-SU-2025:03082-1 Release Date: 2025-09-05T08:27:45Z Rating: low References: * bsc#1249011 Cross-References: * CVE-2025-58160 CVSS scores: * CVE-2025-58160 ( SUSE ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-58160 ( SUSE ): 3.1 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:N * CVE-2025-58160 ( NVD ): 2.3 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: This update for python-maturin fixes the following issues: * CVE-2025-58160: terminal escape injection via ANSI sequences from untrusted input (bsc#1249011). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch SUSE-2025-3082=1 openSUSE-SLE-15.6-2025-3082=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64 i586) * python311-maturin-1.4.0-150600.3.9.1 ## References: * https://www.suse.com/security/cve/CVE-2025-58160.html * https://bugzilla.suse.com/show_bug.cgi?id=1249011 . Important notice concerning python-maturin for openSUSE addressing a minor severity escape injection flaw, enhancing collective security protocols.. openSUSE security update, python-maturin patch, CVE-2025-58160 fix. . Severity: Low. LinuxSecurity.com Team

Calendar%202 Sep 05, 2025 Low OpenSUSE
202

openSUSE Leap 15.6: SUSE-SU-2025:1492-1 moderate: escape injection

An update that solves one vulnerability can now be installed.. # Security update for rubygem-rack-1_6 Announcement ID: SUSE-SU-2025:1492-1 Release Date: 2025-05-06T14:36:05Z Rating: moderate References: * bsc#1238607 Cross-References: * CVE-2025-27111 CVSS scores: * CVE-2025-27111 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-27111 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-27111 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X Affected Products: * openSUSE Leap 15.6 An update that solves one vulnerability can now be installed. ## Description: This update for rubygem-rack-1_6 fixes the following issues: * CVE-2025-27111: Fixed Escape Sequence Injection vulnerability (bsc#1238607) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-1492=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-1_6-1.6.8-150000.3.6.1 * ruby2.5-rubygem-rack-testsuite-1_6-1.6.8-150000.3.6.1 * ruby2.5-rubygem-rack-doc-1_6-1.6.8-150000.3.6.1 ## References: * https://www.suse.com/security/cve/CVE-2025-27111.html * https://bugzilla.suse.com/show_bug.cgi?id=1238607 . Important patch for openSUSE Leap 15.6 tackling escape character injection vulnerability in rubygem-rack-1_6.. openSUSE security update, rubygem rack vulnerability, escape injection remedy. . LinuxSecurity.com Team

Calendar%202 May 07, 2025 OpenSUSE
202

openSUSE Leap 15.6: SUSE-SU-2025:0874-1 important: rubygem-rack injection

An update that solves three vulnerabilities can now be installed.. # Security update for rubygem-rack Announcement ID: SUSE-SU-2025:0874-1 Release Date: 2025-03-14T14:47:55Z Rating: important References: * bsc#1237141 * bsc#1238607 * bsc#1239298 Cross-References: * CVE-2025-25184 * CVE-2025-27111 * CVE-2025-27610 CVSS scores: * CVE-2025-25184 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-25184 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-25184 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-27111 ( SUSE ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-27111 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N * CVE-2025-27111 ( NVD ): 6.9 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-27610 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-27610 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-27610 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.6 * SUSE Linux Enterprise High Availability Extension 15 SP3 * SUSE Linux Enterprise High Availability Extension 15 SP4 * SUSE Linux Enterprise High Availability Extension 15 SP5 * SUSE Linux Enterprise High Availability Extension 15 SP6 * SUSE Linux Enterprise High Performance Computing 15 SP3 * SUSE Linux Enterprise High Performance Computing 15 SP4 * SUSE Linux Enterprise High Performance Computing 15 SP5 * SUSE Linux Enterprise Server 15 SP3 * SUSE Linux Enterprise Server 15 SP3 Business Critical Linux * SUSE Linux Enterprise Server 15 SP4 * SUSE Linux EnterpriseServer 15 SP5 * SUSE Linux Enterprise Server 15 SP6 * SUSE Linux Enterprise Server for SAP Applications 15 SP3 * SUSE Linux Enterprise Server for SAP Applications 15 SP4 * SUSE Linux Enterprise Server for SAP Applications 15 SP5 * SUSE Linux Enterprise Server for SAP Applications 15 SP6 * SUSE Manager Proxy 4.2 * SUSE Manager Proxy 4.3 * SUSE Manager Retail Branch Server 4.2 * SUSE Manager Retail Branch Server 4.3 * SUSE Manager Server 4.2 * SUSE Manager Server 4.3 An update that solves three vulnerabilities can now be installed. ## Description: This update for rubygem-rack fixes the following issues: * CVE-2025-25184: Fixed escape sequence injection vulnerability in rack leading to possible log injection (bsc#1237141) * CVE-2025-27111: Fixed escape sequence injection vulnerability in rack leading to possible log injection (bsc#1238607) * CVE-2025-27610: Fixed improper sanitization of user-supplied paths (bsc#1239298) ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * SUSE Linux Enterprise High Availability Extension 15 SP6 zypper in -t patch SUSE-SLE-Product-HA-15-SP6-2025-874=1 * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-874=1 * SUSE Linux Enterprise High Availability Extension 15 SP3 zypper in -t patch SUSE-SLE-Product-HA-15-SP3-2025-874=1 * SUSE Linux Enterprise High Availability Extension 15 SP4 zypper in -t patch SUSE-SLE-Product-HA-15-SP4-2025-874=1 * SUSE Linux Enterprise High Availability Extension 15 SP5 zypper in -t patch SUSE-SLE-Product-HA-15-SP5-2025-874=1 ## Package List: * SUSE Linux Enterprise High Availability Extension 15 SP6 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-2.0.8-150000.3.26.1 * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-2.0.8-150000.3.26.1 *ruby2.5-rubygem-rack-testsuite-2.0.8-150000.3.26.1 * ruby2.5-rubygem-rack-doc-2.0.8-150000.3.26.1 * SUSE Linux Enterprise High Availability Extension 15 SP3 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-2.0.8-150000.3.26.1 * SUSE Linux Enterprise High Availability Extension 15 SP4 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-2.0.8-150000.3.26.1 * SUSE Linux Enterprise High Availability Extension 15 SP5 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-2.0.8-150000.3.26.1 ## References: * https://www.suse.com/security/cve/CVE-2025-25184.html * https://www.suse.com/security/cve/CVE-2025-27111.html * https://www.suse.com/security/cve/CVE-2025-27610.html * https://bugzilla.suse.com/show_bug.cgi?id=1237141 * https://bugzilla.suse.com/show_bug.cgi?id=1238607 * https://bugzilla.suse.com/show_bug.cgi?id=1239298 . A recent security patch for rubygem-rack resolves multiple serious vulnerabilities impacting openSUSE and SUSE Linux distributions.. openSUSE security, rubygem-rack, SUSE updates, patch management, Linux security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 Mar 14, 2025 Important OpenSUSE
200

SciLinux: SLSA-2019-1235-1 Important Ruby Update - Escape Injection Risks

rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324) * rubygems: Escape sequence injection vulnerability in gem owner (CVE-2019-8322) * rubygems: Escape sequence injection vulnerability in API response handling (CVE-2019-8323) * rubygems: Escape sequence injection vulnerability in errors (CVE-2019-8325) SL7 x86_64 ruby-2.0.0.648-35.el7_6.x86_64.rp [More...]. Synopsis: Important: ruby security update Advisory ID: SLSA-2019:1235-1 Issue Date: 2019-05-15 CVE Numbers: CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 -- Security Fix(es): * rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324) * rubygems: Escape sequence injection vulnerability in gem owner (CVE-2019-8322) * rubygems: Escape sequence injection vulnerability in API response handling (CVE-2019-8323) * rubygems: Escape sequence injection vulnerability in errors(CVE-2019-8325) -- SL7 x86_64 ruby-2.0.0.648-35.el7_6.x86_64.rpm ruby-debuginfo-2.0.0.648-35.el7_6.i686.rpm ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-libs-2.0.0.648-35.el7_6.i686.rpm ruby-libs-2.0.0.648-35.el7_6.x86_64.rpm rubygem-bigdecimal-1.2.0-35.el7_6.x86_64.rpm rubygem-io-console-0.4.2-35.el7_6.x86_64.rpm rubygem-json-1.7.7-35.el7_6.x86_64.rpm rubygem-psych-2.0.0-35.el7_6.x86_64.rpm ruby-devel-2.0.0.648-35.el7_6.x86_64.rpm ruby-tcltk-2.0.0.648-35.el7_6.x86_64.rpm ruby-2.0.0.648-35.el7_6.src.rpm noarch ruby-irb-2.0.0.648-35.el7_6.noarch.rpm rubygem-rdoc-4.0.0-35.el7_6.noarch.rpm rubygems-2.0.14.1-35.el7_6.noarch.rpm ruby-doc-2.0.0.648-35.el7_6.noarch.rpm rubygem-minitest-4.3.2-35.el7_6.noarch.rpm rubygem-rake-0.9.6-35.el7_6.noarch.rpm rubygems-devel-2.0.14.1-35.el7_6.noarch.rpm - Scientific Linux Development Team . Crucial ruby security notice for SL7 regarding vulnerability to escape injection and remote code execution threats. Promptmeasures advised.. ruby security update, rubygems issues, scientific linux advisory, escape injection vulnerabilities. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 15, 2019 Important Scientific Linux
98

RedHat RHSA-2019:1235-01 Important: Ruby Security Threat Update

An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: ruby security update Advisory ID: RHSA-2019:1235-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2019:1235 Issue date: 2019-05-15 CVE Names: CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 ==================================================================== 1. Summary: An update for ruby is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64 Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - noarch, x86_64 Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v. 7) - aarch64, noarch, ppc64le, s390x Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v. 7) - aarch64, noarch, ppc64le, s390x 3. Description: Ruby is anextensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. Security Fix(es): * rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324) * rubygems: Escape sequence injection vulnerability in gem owner (CVE-2019-8322) * rubygems: Escape sequence injection vulnerability in API response handling (CVE-2019-8323) * rubygems: Escape sequence injection vulnerability in errors(CVE-2019-8325) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1692516 - CVE-2019-8322 rubygems: Escape sequence injection vulnerability in gem owner 1692519 - CVE-2019-8323 rubygems: Escape sequence injection vulnerability in API response handling 1692520 - CVE-2019-8324 rubygems: Installing a malicious gem may lead to arbitrary code execution 1692522 - CVE-2019-8325 rubygems: Escape sequence injection vulnerability in errors 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: ruby-2.0.0.648-35.el7_6.src.rpm noarch: ruby-irb-2.0.0.648-35.el7_6.noarch.rpm rubygem-rdoc-4.0.0-35.el7_6.noarch.rpm rubygems-2.0.14.1-35.el7_6.noarch.rpm x86_64: ruby-2.0.0.648-35.el7_6.x86_64.rpm ruby-debuginfo-2.0.0.648-35.el7_6.i686.rpm ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-libs-2.0.0.648-35.el7_6.i686.rpm ruby-libs-2.0.0.648-35.el7_6.x86_64.rpm rubygem-bigdecimal-1.2.0-35.el7_6.x86_64.rpm rubygem-io-console-0.4.2-35.el7_6.x86_64.rpm rubygem-json-1.7.7-35.el7_6.x86_64.rpm rubygem-psych-2.0.0-35.el7_6.x86_64.rpm Red Hat Enterprise Linux Client Optional (v.7): noarch: ruby-doc-2.0.0.648-35.el7_6.noarch.rpm rubygem-minitest-4.3.2-35.el7_6.noarch.rpm rubygem-rake-0.9.6-35.el7_6.noarch.rpm rubygems-devel-2.0.14.1-35.el7_6.noarch.rpm x86_64: ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-devel-2.0.0.648-35.el7_6.x86_64.rpm ruby-tcltk-2.0.0.648-35.el7_6.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: ruby-2.0.0.648-35.el7_6.src.rpm noarch: ruby-irb-2.0.0.648-35.el7_6.noarch.rpm rubygem-rdoc-4.0.0-35.el7_6.noarch.rpm rubygems-2.0.14.1-35.el7_6.noarch.rpm x86_64: ruby-2.0.0.648-35.el7_6.x86_64.rpm ruby-debuginfo-2.0.0.648-35.el7_6.i686.rpm ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-libs-2.0.0.648-35.el7_6.i686.rpm ruby-libs-2.0.0.648-35.el7_6.x86_64.rpm rubygem-bigdecimal-1.2.0-35.el7_6.x86_64.rpm rubygem-io-console-0.4.2-35.el7_6.x86_64.rpm rubygem-json-1.7.7-35.el7_6.x86_64.rpm rubygem-psych-2.0.0-35.el7_6.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): noarch: ruby-doc-2.0.0.648-35.el7_6.noarch.rpm rubygem-minitest-4.3.2-35.el7_6.noarch.rpm rubygem-rake-0.9.6-35.el7_6.noarch.rpm rubygems-devel-2.0.14.1-35.el7_6.noarch.rpm x86_64: ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-devel-2.0.0.648-35.el7_6.x86_64.rpm ruby-tcltk-2.0.0.648-35.el7_6.x86_64.rpm Red Hat Enterprise Linux Server (v.7): Source: ruby-2.0.0.648-35.el7_6.src.rpm noarch: ruby-irb-2.0.0.648-35.el7_6.noarch.rpm rubygem-rdoc-4.0.0-35.el7_6.noarch.rpm rubygems-2.0.14.1-35.el7_6.noarch.rpm ppc64: ruby-2.0.0.648-35.el7_6.ppc64.rpm ruby-debuginfo-2.0.0.648-35.el7_6.ppc.rpm ruby-debuginfo-2.0.0.648-35.el7_6.ppc64.rpm ruby-libs-2.0.0.648-35.el7_6.ppc.rpm ruby-libs-2.0.0.648-35.el7_6.ppc64.rpm rubygem-bigdecimal-1.2.0-35.el7_6.ppc64.rpm rubygem-io-console-0.4.2-35.el7_6.ppc64.rpm rubygem-json-1.7.7-35.el7_6.ppc64.rpm rubygem-psych-2.0.0-35.el7_6.ppc64.rpm ppc64le: ruby-2.0.0.648-35.el7_6.ppc64le.rpm ruby-debuginfo-2.0.0.648-35.el7_6.ppc64le.rpm ruby-libs-2.0.0.648-35.el7_6.ppc64le.rpm rubygem-bigdecimal-1.2.0-35.el7_6.ppc64le.rpm rubygem-io-console-0.4.2-35.el7_6.ppc64le.rpm rubygem-json-1.7.7-35.el7_6.ppc64le.rpm rubygem-psych-2.0.0-35.el7_6.ppc64le.rpm s390x: ruby-2.0.0.648-35.el7_6.s390x.rpm ruby-debuginfo-2.0.0.648-35.el7_6.s390.rpm ruby-debuginfo-2.0.0.648-35.el7_6.s390x.rpm ruby-libs-2.0.0.648-35.el7_6.s390.rpm ruby-libs-2.0.0.648-35.el7_6.s390x.rpm rubygem-bigdecimal-1.2.0-35.el7_6.s390x.rpm rubygem-io-console-0.4.2-35.el7_6.s390x.rpm rubygem-json-1.7.7-35.el7_6.s390x.rpm rubygem-psych-2.0.0-35.el7_6.s390x.rpm x86_64: ruby-2.0.0.648-35.el7_6.x86_64.rpm ruby-debuginfo-2.0.0.648-35.el7_6.i686.rpm ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-libs-2.0.0.648-35.el7_6.i686.rpm ruby-libs-2.0.0.648-35.el7_6.x86_64.rpm rubygem-bigdecimal-1.2.0-35.el7_6.x86_64.rpm rubygem-io-console-0.4.2-35.el7_6.x86_64.rpm rubygem-json-1.7.7-35.el7_6.x86_64.rpm rubygem-psych-2.0.0-35.el7_6.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server (v.7): Source: ruby-2.0.0.648-35.el7_6.src.rpm aarch64: ruby-2.0.0.648-35.el7_6.aarch64.rpm ruby-debuginfo-2.0.0.648-35.el7_6.aarch64.rpm ruby-libs-2.0.0.648-35.el7_6.aarch64.rpm rubygem-bigdecimal-1.2.0-35.el7_6.aarch64.rpm rubygem-io-console-0.4.2-35.el7_6.aarch64.rpm rubygem-json-1.7.7-35.el7_6.aarch64.rpm rubygem-psych-2.0.0-35.el7_6.aarch64.rpm noarch: ruby-irb-2.0.0.648-35.el7_6.noarch.rpm rubygem-rdoc-4.0.0-35.el7_6.noarch.rpm rubygems-2.0.14.1-35.el7_6.noarch.rpm ppc64le: ruby-2.0.0.648-35.el7_6.ppc64le.rpm ruby-debuginfo-2.0.0.648-35.el7_6.ppc64le.rpm ruby-libs-2.0.0.648-35.el7_6.ppc64le.rpm rubygem-bigdecimal-1.2.0-35.el7_6.ppc64le.rpm rubygem-io-console-0.4.2-35.el7_6.ppc64le.rpm rubygem-json-1.7.7-35.el7_6.ppc64le.rpm rubygem-psych-2.0.0-35.el7_6.ppc64le.rpm s390x: ruby-2.0.0.648-35.el7_6.s390x.rpm ruby-debuginfo-2.0.0.648-35.el7_6.s390.rpm ruby-debuginfo-2.0.0.648-35.el7_6.s390x.rpm ruby-libs-2.0.0.648-35.el7_6.s390.rpm ruby-libs-2.0.0.648-35.el7_6.s390x.rpm rubygem-bigdecimal-1.2.0-35.el7_6.s390x.rpm rubygem-io-console-0.4.2-35.el7_6.s390x.rpm rubygem-json-1.7.7-35.el7_6.s390x.rpm rubygem-psych-2.0.0-35.el7_6.s390x.rpm Red Hat Enterprise Linux Server Optional (v. 7): noarch: ruby-doc-2.0.0.648-35.el7_6.noarch.rpm rubygem-minitest-4.3.2-35.el7_6.noarch.rpm rubygem-rake-0.9.6-35.el7_6.noarch.rpm rubygems-devel-2.0.14.1-35.el7_6.noarch.rpm ppc64: ruby-debuginfo-2.0.0.648-35.el7_6.ppc64.rpm ruby-devel-2.0.0.648-35.el7_6.ppc64.rpm ruby-tcltk-2.0.0.648-35.el7_6.ppc64.rpm ppc64le: ruby-debuginfo-2.0.0.648-35.el7_6.ppc64le.rpm ruby-devel-2.0.0.648-35.el7_6.ppc64le.rpm ruby-tcltk-2.0.0.648-35.el7_6.ppc64le.rpm s390x: ruby-debuginfo-2.0.0.648-35.el7_6.s390x.rpm ruby-devel-2.0.0.648-35.el7_6.s390x.rpm ruby-tcltk-2.0.0.648-35.el7_6.s390x.rpm x86_64: ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-devel-2.0.0.648-35.el7_6.x86_64.rpm ruby-tcltk-2.0.0.648-35.el7_6.x86_64.rpm Red Hat Enterprise Linux for ARM and IBM Power LE (POWER9) Server Optional (v.7): aarch64: ruby-debuginfo-2.0.0.648-35.el7_6.aarch64.rpm ruby-devel-2.0.0.648-35.el7_6.aarch64.rpm ruby-tcltk-2.0.0.648-35.el7_6.aarch64.rpm noarch: ruby-doc-2.0.0.648-35.el7_6.noarch.rpm rubygem-minitest-4.3.2-35.el7_6.noarch.rpm rubygem-rake-0.9.6-35.el7_6.noarch.rpm rubygems-devel-2.0.14.1-35.el7_6.noarch.rpm ppc64le: ruby-debuginfo-2.0.0.648-35.el7_6.ppc64le.rpm ruby-devel-2.0.0.648-35.el7_6.ppc64le.rpm ruby-tcltk-2.0.0.648-35.el7_6.ppc64le.rpm s390x: ruby-debuginfo-2.0.0.648-35.el7_6.s390x.rpm ruby-devel-2.0.0.648-35.el7_6.s390x.rpm ruby-tcltk-2.0.0.648-35.el7_6.s390x.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: ruby-2.0.0.648-35.el7_6.src.rpm noarch: ruby-irb-2.0.0.648-35.el7_6.noarch.rpm rubygem-rdoc-4.0.0-35.el7_6.noarch.rpm rubygems-2.0.14.1-35.el7_6.noarch.rpm x86_64: ruby-2.0.0.648-35.el7_6.x86_64.rpm ruby-debuginfo-2.0.0.648-35.el7_6.i686.rpm ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-libs-2.0.0.648-35.el7_6.i686.rpm ruby-libs-2.0.0.648-35.el7_6.x86_64.rpm rubygem-bigdecimal-1.2.0-35.el7_6.x86_64.rpm rubygem-io-console-0.4.2-35.el7_6.x86_64.rpm rubygem-json-1.7.7-35.el7_6.x86_64.rpm rubygem-psych-2.0.0-35.el7_6.x86_64.rpm Red Hat Enterprise Linux Workstation Optional (v. 7): noarch: ruby-doc-2.0.0.648-35.el7_6.noarch.rpm rubygem-minitest-4.3.2-35.el7_6.noarch.rpm rubygem-rake-0.9.6-35.el7_6.noarch.rpm rubygems-devel-2.0.14.1-35.el7_6.noarch.rpm x86_64: ruby-debuginfo-2.0.0.648-35.el7_6.x86_64.rpm ruby-devel-2.0.0.648-35.el7_6.x86_64.rpm ruby-tcltk-2.0.0.648-35.el7_6.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2019-8322 https://access.redhat.com/security/cve/CVE-2019-8323 https://access.redhat.com/security/cve/CVE-2019-8324 https://access.redhat.com/security/cve/CVE-2019-8325 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hatsecurity contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXNxSQtzjgjWX9erEAQgYWQ/+LQju2DcqN4JOuccPOQcvRd0hhIgRjuyS sxohBdIomZSBafEGpxNCoVnsEBYcCeaYSi0zG3mItMsh+SHuhegFs6EBGB1DYIBj zjMIpF4Z+jH0mPCxcMxt6XCHXCFCQ8X9tBeq+TYOlXooXIjdilrz2BO3Of+nM2Nz PKO455nTcWt4SdU4iBMKTTEKC6boVM/ch7KjPsp5yMg+j4zcua9n+ZAz7TNQurIn 61Vgjyp9ErMc9xHkQ9ucRBF3J99njqNa0vefQq3Hrmil5YyINsnCpEr2biF7Eo0z mMHuVdUjLbaLsDL/Ol7PK1fvkUjTXPm3OegK6D6OQxBeIhAiCByVNyyl3sIruu1D F1YEH2sgNsXngUHZXoVbZGCo+QSpW9sD2j53c2oxqORnOWViLDOWELq4cIz1kw6u Fp3eagiilu9QrtkAfKnulw2hr7QLgwwXXlbC5x+jljWNjg/QxDoMmM4YD3R8kuvs 16sQqvfrVpAgHcSoCPOeZOeZ72lnj54Qntaiq5m4aK4B6QPAFVQjr6jsHaTSMoA+ hRmZbKaWsJllpKkFa1k+wybyHHL3pmGQ1ItspTdqGomOwuP23VkhJfMXCkBic9Eo dwq6fVOM3TRNikGp9FiX5pLi8ITghOtywxpif6KQsZRL57bhUHJkuW3SH+gyJaBJ Tm9Z8smpjA0=YTMt -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ====================================================. update, enterprise, linux, product, security. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 15, 2019 Important Red Hat
98

Red Hat Enterprise: RHSA-2019-1148-01 Important: Ruby Security Fix

An update for rh-ruby25-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-ruby25-ruby security, bug fix, and enhancement update Advisory ID: RHSA-2019:1148-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2019:1148 Issue date: 2019-05-13 CVE Names: CVE-2019-8320 CVE-2019-8321 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 ==================================================================== 1. Summary: An update for rh-ruby25-ruby is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - aarch64, noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch, ppc64le, s390x, x86_64 Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64 3. Description: Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks. The following packages have been upgraded to a later upstreamversion: rh-ruby25-ruby (2.5.5). (BZ#1700274) Security Fix(es): * rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324) * rubygems: Delete directory using symlink when decompressing tar (CVE-2019-8320) * rubygems: Escape sequence injection vulnerability in verbose (CVE-2019-8321) * rubygems: Escape sequence injection vulnerability in gem owner (CVE-2019-8322) * rubygems: Escape sequence injection vulnerability in API response handling (CVE-2019-8323) * rubygems: Escape sequence injection vulnerability in errors(CVE-2019-8325) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1692512 - CVE-2019-8320 rubygems: Delete directory using symlink when decompressing tar 1692514 - CVE-2019-8321 rubygems: Escape sequence injection vulnerability in verbose 1692516 - CVE-2019-8322 rubygems: Escape sequence injection vulnerability in gem owner 1692519 - CVE-2019-8323 rubygems: Escape sequence injection vulnerability in API response handling 1692520 - CVE-2019-8324 rubygems: Installing a malicious gem may lead to arbitrary code execution 1692522 - CVE-2019-8325 rubygems: Escape sequence injection vulnerability in errors1700274 - Rebase to the latest Ruby 2.5 point release [3.2.z] 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-ruby25-ruby-2.5.5-7.el7.src.rpm aarch64: rh-ruby25-ruby-2.5.5-7.el7.aarch64.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.aarch64.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.aarch64.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.aarch64.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.aarch64.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.aarch64.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.aarch64.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.aarch64.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.aarch64.rpm noarch: rh-ruby25-ruby-doc-2.5.5-7.el7.noarch.rpm rh-ruby25-ruby-irb-2.5.5-7.el7.noarch.rpm rh-ruby25-rubygem-did_you_mean-1.2.0-7.el7.noarch.rpm rh-ruby25-rubygem-minitest-5.10.3-7.el7.noarch.rpm rh-ruby25-rubygem-net-telnet-0.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-power_assert-1.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-rake-12.3.0-7.el7.noarch.rpm rh-ruby25-rubygem-rdoc-6.0.1-7.el7.noarch.rpm rh-ruby25-rubygem-test-unit-3.2.7-7.el7.noarch.rpm rh-ruby25-rubygem-xmlrpc-0.3.0-7.el7.noarch.rpm rh-ruby25-rubygems-2.7.6.2-7.el7.noarch.rpm rh-ruby25-rubygems-devel-2.7.6.2-7.el7.noarch.rpm ppc64le: rh-ruby25-ruby-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.ppc64le.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.ppc64le.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.ppc64le.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.ppc64le.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.ppc64le.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.ppc64le.rpm s390x: rh-ruby25-ruby-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.s390x.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.s390x.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.s390x.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.s390x.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.s390x.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.s390x.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v.7): Source: rh-ruby25-ruby-2.5.5-7.el7.src.rpm aarch64: rh-ruby25-ruby-2.5.5-7.el7.aarch64.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.aarch64.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.aarch64.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.aarch64.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.aarch64.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.aarch64.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.aarch64.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.aarch64.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.aarch64.rpm noarch: rh-ruby25-ruby-doc-2.5.5-7.el7.noarch.rpm rh-ruby25-ruby-irb-2.5.5-7.el7.noarch.rpm rh-ruby25-rubygem-did_you_mean-1.2.0-7.el7.noarch.rpm rh-ruby25-rubygem-minitest-5.10.3-7.el7.noarch.rpm rh-ruby25-rubygem-net-telnet-0.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-power_assert-1.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-rake-12.3.0-7.el7.noarch.rpm rh-ruby25-rubygem-rdoc-6.0.1-7.el7.noarch.rpm rh-ruby25-rubygem-test-unit-3.2.7-7.el7.noarch.rpm rh-ruby25-rubygem-xmlrpc-0.3.0-7.el7.noarch.rpm rh-ruby25-rubygems-2.7.6.2-7.el7.noarch.rpm rh-ruby25-rubygems-devel-2.7.6.2-7.el7.noarch.rpm ppc64le: rh-ruby25-ruby-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.ppc64le.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.ppc64le.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.ppc64le.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.ppc64le.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.ppc64le.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.ppc64le.rpm s390x: rh-ruby25-ruby-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.s390x.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.s390x.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.s390x.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.s390x.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.s390x.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.s390x.rpm x86_64: rh-ruby25-ruby-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.x86_64.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.x86_64.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.x86_64.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.x86_64.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.x86_64.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.4): Source: rh-ruby25-ruby-2.5.5-7.el7.src.rpm noarch: rh-ruby25-ruby-doc-2.5.5-7.el7.noarch.rpm rh-ruby25-ruby-irb-2.5.5-7.el7.noarch.rpm rh-ruby25-rubygem-did_you_mean-1.2.0-7.el7.noarch.rpm rh-ruby25-rubygem-minitest-5.10.3-7.el7.noarch.rpm rh-ruby25-rubygem-net-telnet-0.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-power_assert-1.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-rake-12.3.0-7.el7.noarch.rpm rh-ruby25-rubygem-rdoc-6.0.1-7.el7.noarch.rpm rh-ruby25-rubygem-test-unit-3.2.7-7.el7.noarch.rpm rh-ruby25-rubygem-xmlrpc-0.3.0-7.el7.noarch.rpm rh-ruby25-rubygems-2.7.6.2-7.el7.noarch.rpm rh-ruby25-rubygems-devel-2.7.6.2-7.el7.noarch.rpm ppc64le: rh-ruby25-ruby-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.ppc64le.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.ppc64le.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.ppc64le.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.ppc64le.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.ppc64le.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.ppc64le.rpm s390x: rh-ruby25-ruby-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.s390x.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.s390x.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.s390x.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.s390x.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.s390x.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.s390x.rpm x86_64: rh-ruby25-ruby-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.x86_64.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.x86_64.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.x86_64.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.x86_64.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.x86_64.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.5): Source: rh-ruby25-ruby-2.5.5-7.el7.src.rpm noarch: rh-ruby25-ruby-doc-2.5.5-7.el7.noarch.rpm rh-ruby25-ruby-irb-2.5.5-7.el7.noarch.rpm rh-ruby25-rubygem-did_you_mean-1.2.0-7.el7.noarch.rpm rh-ruby25-rubygem-minitest-5.10.3-7.el7.noarch.rpm rh-ruby25-rubygem-net-telnet-0.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-power_assert-1.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-rake-12.3.0-7.el7.noarch.rpm rh-ruby25-rubygem-rdoc-6.0.1-7.el7.noarch.rpm rh-ruby25-rubygem-test-unit-3.2.7-7.el7.noarch.rpm rh-ruby25-rubygem-xmlrpc-0.3.0-7.el7.noarch.rpm rh-ruby25-rubygems-2.7.6.2-7.el7.noarch.rpm rh-ruby25-rubygems-devel-2.7.6.2-7.el7.noarch.rpm ppc64le: rh-ruby25-ruby-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.ppc64le.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.ppc64le.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.ppc64le.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.ppc64le.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.ppc64le.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.ppc64le.rpm s390x: rh-ruby25-ruby-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.s390x.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.s390x.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.s390x.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.s390x.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.s390x.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.s390x.rpm x86_64: rh-ruby25-ruby-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.x86_64.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.x86_64.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.x86_64.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.x86_64.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.x86_64.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v.7.6): Source: rh-ruby25-ruby-2.5.5-7.el7.src.rpm noarch: rh-ruby25-ruby-doc-2.5.5-7.el7.noarch.rpm rh-ruby25-ruby-irb-2.5.5-7.el7.noarch.rpm rh-ruby25-rubygem-did_you_mean-1.2.0-7.el7.noarch.rpm rh-ruby25-rubygem-minitest-5.10.3-7.el7.noarch.rpm rh-ruby25-rubygem-net-telnet-0.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-power_assert-1.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-rake-12.3.0-7.el7.noarch.rpm rh-ruby25-rubygem-rdoc-6.0.1-7.el7.noarch.rpm rh-ruby25-rubygem-test-unit-3.2.7-7.el7.noarch.rpm rh-ruby25-rubygem-xmlrpc-0.3.0-7.el7.noarch.rpm rh-ruby25-rubygems-2.7.6.2-7.el7.noarch.rpm rh-ruby25-rubygems-devel-2.7.6.2-7.el7.noarch.rpm ppc64le: rh-ruby25-ruby-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.ppc64le.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.ppc64le.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.ppc64le.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.ppc64le.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.ppc64le.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.ppc64le.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.ppc64le.rpm s390x: rh-ruby25-ruby-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.s390x.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.s390x.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.s390x.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.s390x.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.s390x.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.s390x.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.s390x.rpm x86_64: rh-ruby25-ruby-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.x86_64.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.x86_64.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.x86_64.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.x86_64.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.x86_64.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.x86_64.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v.7): Source: rh-ruby25-ruby-2.5.5-7.el7.src.rpm noarch: rh-ruby25-ruby-doc-2.5.5-7.el7.noarch.rpm rh-ruby25-ruby-irb-2.5.5-7.el7.noarch.rpm rh-ruby25-rubygem-did_you_mean-1.2.0-7.el7.noarch.rpm rh-ruby25-rubygem-minitest-5.10.3-7.el7.noarch.rpm rh-ruby25-rubygem-net-telnet-0.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-power_assert-1.1.1-7.el7.noarch.rpm rh-ruby25-rubygem-rake-12.3.0-7.el7.noarch.rpm rh-ruby25-rubygem-rdoc-6.0.1-7.el7.noarch.rpm rh-ruby25-rubygem-test-unit-3.2.7-7.el7.noarch.rpm rh-ruby25-rubygem-xmlrpc-0.3.0-7.el7.noarch.rpm rh-ruby25-rubygems-2.7.6.2-7.el7.noarch.rpm rh-ruby25-rubygems-devel-2.7.6.2-7.el7.noarch.rpm x86_64: rh-ruby25-ruby-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-debuginfo-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-devel-2.5.5-7.el7.x86_64.rpm rh-ruby25-ruby-libs-2.5.5-7.el7.x86_64.rpm rh-ruby25-rubygem-bigdecimal-1.3.4-7.el7.x86_64.rpm rh-ruby25-rubygem-io-console-0.4.6-7.el7.x86_64.rpm rh-ruby25-rubygem-json-2.1.0-7.el7.x86_64.rpm rh-ruby25-rubygem-openssl-2.1.2-7.el7.x86_64.rpm rh-ruby25-rubygem-psych-3.0.2-7.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-8320 https://access.redhat.com/security/cve/CVE-2019-8321 https://access.redhat.com/security/cve/CVE-2019-8322 https://access.redhat.com/security/cve/CVE-2019-8323 https://access.redhat.com/security/cve/CVE-2019-8324 https://access.redhat.com/security/cve/CVE-2019-8325 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPGv1 iQIVAwUBXNky2dzjgjWX9erEAQjM6Q/+L9XVFVe18BoLRP6NdFsmgo9w8LsBKt5i ptWBi+wKgNpaTTf8/AyW/1aV6BkGAYaRMgL29ltOnI00hd4szq6yUcMbsUg6lIRq 0zkLay88S8ZxON5f4Qy+dP3IhfjVQ4X8B5UCJgDv4riGw77M0RPF6cu73aSdcmXR TYxKFw/NBK5l9nHb86qALj6x7qMI+1GWMbY4xo1z5erwWDRJCla/kbg3SqwM04F5 8S+VkDK8I30KVYF2lglNWjlCcct0XIqxbRWMG0ONuWpzecLq7TLmxPDOGRwiNhoJ kbwNEOYsDntF09whfCDm+aylYygcF0DullrWa6JIDZLWmkEsd1yXbIddRL5DEOLy QK8mnJvTz8vvysxpkcxjfcTxzroga14XR9r0cO1e7EwPTlL7LiGMMvB5v+qSxRV4 Vt4N578HbFzqg9c29F9z5CZV9xseKSa00Te2pT2wBUg6xXNnrCcda9CDhNN4PDMx VOTTAcYXCkCWj1Row6CIda1CsD8BkbZxmPONxWREcTmoYNl8sQLNEbf0r3SpaSlo STMG2SUxb6+jNaYSn8KXwvUhG9jsBBYwKnZM8bRzQu5/nLhPwr8+ftjIfafTsXdQ LC9k9OFsBGnu7wi9I46O8/UADwoWWPBL8vsPMlcQnh2UMi+m41RHpFOmND3msP3g fqP5UZxEQFM=Jkbr -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . Security alert regarding rh-ruby25-ruby patch that tackles vital vulnerabilities, encompassing severe security issues and corrections.. Red Hat, Ruby, security advisory, software update, bug fix. . Severity: Important. LinuxSecurity.com Team

Calendar%202 May 13, 2019 Important Red Hat
197

Debian 8 Jessie DLA-1735-1 Critical Ruby2.1 Escape Injection Threat

Several vulnerabilities have been discovered in rubygems embedded in ruby2.1, the interpreted scripting language. . Package : ruby2.1 Version : 2.1.5-2+deb8u7 CVE ID : CVE-2019-8320 CVE-2019-8322 CVE-2019-8323 CVE-2019-8324 CVE-2019-8325 Several vulnerabilities have been discovered in rubygems embedded in ruby2.1, the interpreted scripting language. CVE-2019-8320 A Directory Traversal issue was discovered in RubyGems. Before making new directories or touching files (which now include path-checking code for symlinks), it would delete the target destination. CVE-2019-8322 The gem owner command outputs the contents of the API response directly to stdout. Therefore, if the response is crafted, escape sequence injection may occur. CVE-2019-8323 Gem::GemcutterUtilities#with_response may output the API response to stdout as it is. Therefore, if the API side modifies the response, escape sequence injection may occur. CVE-2019-8324 A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ensure_loadable_spec during the preinstall check. CVE-2019-8325 An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since Gem::CommandManager#run calls alert_error without escaping, escape sequence injection is possible. (There are many ways to cause an error.) For Debian 8 "Jessie", these problems have been fixed in version 2.1.5-2+deb8u7. We recommend that you upgrade your ruby2.1 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Package : ruby2.1 Version : 2.1.5-2+deb8u7 CVE ID : CVE-2019-8320 CVE-2019-8322 CVE-2019-8323 CVE-20. vulnerabilities, rubygems, embedded, ruby2, interpreted, script. . Severity: Critical. LinuxSecurity.com Team

Calendar%202 Mar 29, 2019 Critical Debian LTS
98

RedHat OpenStack 13.0 RHSA-2018:2225-01 Moderate: Fluentd Escape Injection

An update for fluentd is now available for Red Hat OpenStack Platform 13.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Moderate: fluentd security update Advisory ID: RHSA-2018:2225-01 Product: Red Hat Enterprise Linux OpenStack Platform Advisory URL: https://access.redhat.com/errata/RHSA-2018:2225 Issue date: 2018-07-19 CVE Names: CVE-2017-10906 ==================================================================== 1. Summary: An update for fluentd is now available for Red Hat OpenStack Platform 13.0 Operational Tools for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat OpenStack Platform 13.0 Operational Tools for RHEL 7 - noarch 3. Description: Fluentd is an open source data collector designed to scale and simplify log management. It can collect, process and ship many kinds of data in near real-time. The following packages have been upgraded to a later upstream version: fluentd (0.12.41). (BZ#1552379) Security Fix(es): * fluentd: Escape sequence injection in filter_parser.rb:filter_stream can lead to arbitrary command execution when processing logs (CVE-2017-10906) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory,refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1524783 - CVE-2017-10906 fluentd: Escape sequence injection in filter_parser.rb:filter_stream can lead to arbitrary command execution when processing logs 6. Package List: Red Hat OpenStack Platform 13.0 Operational Tools for RHEL 7: Source: fluentd-0.12.41-1.el7.src.rpm noarch: fluentd-0.12.41-1.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2017-10906 https://access.redhat.com/security/updates/classification/#moderate 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2018 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBW1CXENzjgjWX9erEAQgfDg/6AojmNRENUyPNwQabwq2RpnU2GjBuTrcN c2ittpk8qDbb6lMd9u3CblrGVS/yPXcYrKWd0X0elnvqMgWA5CvrX5JSc9VQcAFl 94LRyD8FMaxyc7Sn+RDSjX05JmHrzNFbSowcZoXMmMQNN25d5WKbhYe8FI6ISojQ 5m/0fwazGNuSwPATmezSbCFTdIPZwP4TqjfWojjF6PqEWTpbgHQA91Re3bxNc6KX SPpCNUlGuOPyI6A0cnuYn9xU9P3kmnQnMAudyD82huE5SYNnFGZEhUpdGQ2Jks/e /NjCV+wCoBZv7YZM2W+TqniiwVkftI3RGajg52PfVmMYcvtQi1dUn2VzZr07jVKV haPLw/PC2PoCsMIdE4tU+Kr2UdOSDcXYFv1GGvlNREXE8amhObbGePXszhcjVhtn IuXCpQQ/fHux4n3BOhRuKXuFwXPFAMj5wdMXuQgt7PLQmDW5JoDpEaQEHrRQlyqn w+QkS1n72L6pnfrHeYVzEKC/kuBu3Kf4wp0nIEnXWAQqzbOzWJfzTHAMAOJYjD7K e0de92JSKoigPHk3ApgqNVB2lhFg5+QMzeVB+lYXd+aPRMpZGD99MBZpMDHQcxYx KV4v0lGre0pp+okk6BRljqBI1+0FMdv0BfzgI398hedZo+wmdZwm4Qy106vp+Zg4 8+U100gsnzw=u9T5 -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. . The recent security patch for Red Hat OpenStack Platform 13.0 tackles vulnerabilities related to injection of escape sequences in Fluentd. Discover additional details!. fluentd update, redhat advisory, openstack operational, security update, escape injection. . Severity: Important.LinuxSecurity.com Team

Calendar%202 Jul 19, 2018 Important Red Hat
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

Should Linux servers automatically install security updates?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/157-should-linux-servers-automatically-install-security-updates?task=poll.vote&format=json
157
radio
0
[{"id":506,"title":"Yes \u2014 critical security patches should install automatically.","votes":0,"type":"x","order":1,"pct":0,"resources":[]},{"id":507,"title":"No \u2014 every update should be tested before deployment.","votes":0,"type":"x","order":2,"pct":0,"resources":[]},{"id":508,"title":"Only critical vulnerabilities should auto-install.","votes":0,"type":"x","order":3,"pct":0,"resources":[]},{"id":509,"title":"I patch when Reddit starts panicking.","votes":1,"type":"x","order":4,"pct":100,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200