An update that solves two vulnerabilities can now be installed.. # Security update for rubygem-rack-1_6 Announcement ID: SUSE-SU-2025:0858-1 Release Date: 2025-03-13T17:58:53Z Rating: important References: * bsc#1237141 * bsc#1239298 Cross-References: * CVE-2025-25184 * CVE-2025-27610 CVSS scores: * CVE-2025-25184 ( SUSE ): 5.3 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N * CVE-2025-25184 ( SUSE ): 4.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N * CVE-2025-25184 ( NVD ): 5.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X * CVE-2025-27610 ( SUSE ): 8.7 CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N * CVE-2025-27610 ( SUSE ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N * CVE-2025-27610 ( NVD ): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N Affected Products: * openSUSE Leap 15.6 An update that solves two vulnerabilities can now be installed. ## Description: This update for rubygem-rack-1_6 fixes the following issues: * CVE-2025-27610: Fixed improper sanitization of user-supplied paths when serving files leading to local file inclusion (bsc#1239298). * CVE-2025-25184: Fixed Rack::CommonLogger log entry manipulation (bsc#1237141). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: * openSUSE Leap 15.6 zypper in -t patch openSUSE-SLE-15.6-2025-858=1 ## Package List: * openSUSE Leap 15.6 (aarch64 ppc64le s390x x86_64) * ruby2.5-rubygem-rack-1_6-1.6.8-150000.3.3.1 * ruby2.5-rubygem-rack-testsuite-1_6-1.6.8-150000.3.3.1 * ruby2.5-rubygem-rack-doc-1_6-1.6.8-150000.3.3.1 ## References: * https://www.suse.com/security/cve/CVE-2025-25184.html *https://www.suse.com/security/cve/CVE-2025-27610.html * https://bugzilla.suse.com/show_bug.cgi?id=1237141 * https://bugzilla.suse.com/show_bug.cgi?id=1239298 . An important security update for openSUSE fixes two critical issues in rubygem-rack. Stay secure and patch now!. update, solves, vulnerabilities, installed, security, rubygem-rack-1. . Severity: Important. LinuxSecurity.com Team
Multiple security issues were discovered in PostgreSQL, which may result in the execution of arbitrary code, privilege escalation or log manipulation. For the stable distribution (bookworm), these problems have been fixed in . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5812-1
Get the latest Linux and open source security news straight to your inbox.