The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2024-1431 https://linux.oracle.com/errata/ELSA-2024-1431.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable LinuxNetwork: x86_64: ruby-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm ruby-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm ruby-bundled-gems-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm ruby-bundled-gems-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm ruby-default-gems-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm ruby-devel-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm ruby-devel-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm ruby-doc-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-abrt-0.4.0-1.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-abrt-doc-0.4.0-1.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-bigdecimal-3.1.1-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm rubygem-bigdecimal-3.1.1-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm rubygem-bundler-2.3.26-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-io-console-0.5.11-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm rubygem-io-console-0.5.11-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm rubygem-irb-1.4.1-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-json-2.6.1-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm rubygem-json-2.6.1-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm rubygem-minitest-5.15.0-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-mysql2-0.5.3-3.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm rubygem-mysql2-doc-0.5.3-3.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-pg-1.3.2-1.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm rubygem-pg-doc-1.3.2-1.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-power_assert-2.0.1-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-psych-4.0.4-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm rubygem-psych-4.0.4-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm rubygem-rake-13.0.6-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-rbs-2.7.0-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm rubygem-rbs-2.7.0-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm rubygem-rdoc-6.4.0-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-rexml-3.2.5-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-rss-0.2.9-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygems-3.3.26-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygems-devel-3.3.26-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-test-unit-3.5.3-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-typeprof-0.21.3-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm ruby-libs-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.i686.rpm ruby-libs-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.x86_64.rpm aarch64: ruby-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm ruby-bundled-gems-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm ruby-default-gems-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm ruby-devel-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm ruby-doc-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-abrt-0.4.0-1.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-abrt-doc-0.4.0-1.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-bigdecimal-3.1.1-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm rubygem-bundler-2.3.26-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-io-console-0.5.11-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm rubygem-irb-1.4.1-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-json-2.6.1-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm rubygem-minitest-5.15.0-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-mysql2-0.5.3-3.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm rubygem-mysql2-doc-0.5.3-3.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-pg-1.3.2-1.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm rubygem-pg-doc-1.3.2-1.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-power_assert-2.0.1-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-psych-4.0.4-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm rubygem-rake-13.0.6-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-rbs-2.7.0-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm rubygem-rdoc-6.4.0-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-rexml-3.2.5-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-rss-0.2.9-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygems-3.3.26-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygems-devel-3.3.26-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-test-unit-3.5.3-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm rubygem-typeprof-0.21.3-142.module+el8.9.0+90182+7bdfc9e5.noarch.rpm ruby-libs-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.aarch64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//ruby-3.1.4-142.module+el8.9.0+90182+7bdfc9e5.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//rubygem-abrt-0.4.0-1.module+el8.9.0+90182+7bdfc9e5.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//rubygem-mysql2-0.5.3-3.module+el8.9.0+90182+7bdfc9e5.src.rpm https://oss.oracle.com:443/ol8/SRPMS-updates//rubygem-pg-1.3.2-1.module+el8.9.0+90182+7bdfc9e5.src.rpm Related CVEs: CVE-2021-33621 CVE-2023-28755 CVE-2023-28756 CVE-2023-36617 Description of changes: ruby [3.1.4-142] - Upgrade to Ruby 3.1.4. Resolves: RHEL-28565 - Fix HTTP response splitting in CGI. Resolves: RHEL-28564 - Fix ReDos vulnerability in URI. Resolves: RHEL-28567 Resolves: RHEL-28576 - Fix ReDos vulnerability in Time. Resolves: RHEL-28566 - Make RDoc soft dependency in IRB. Resolves: RHEL-28569 rubygem-abrt [0.4.0-1] - Update to abrt 0.4.0. Resolves: rhbz#1842476 rubygem-mysql2 [0.5.3-3] - Fix SSL related test failure by backporting Fedora commit . Related: RHEL-28565 rubygem-pg [1.3.2-1] - Update to pg 1.3.2 by merging Fedora rawhide branch (commit: 39bbd1b) Resolves: rhbz#2063772 _______________________________________________ El-errata mailing list
Fix: Multiple vulnerabilities in RubyGems https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-40ed78700c 2018-03-02 16:23:59.092551 --------------------------------------------------------------------------------Name : ruby Product : Fedora 27 Version : 2.4.3 Release : 87.fc27 URL : https://www.ruby-lang.org/ Summary : An interpreter of object-oriented scripting language Description : Ruby is the interpreted scripting language for quick and easy object-oriented programming. It has many features to process text files and to do system management tasks (as in Perl). It is simple, straight-forward, and extensible. --------------------------------------------------------------------------------Update Information: Fix: Multiple vulnerabilities in RubyGems https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/ --------------------------------------------------------------------------------References: [ 1 ] Bug #1547431 - CVE-2018-1000073 CVE-2018-1000074 CVE-2018-1000075 CVE-2018-1000076 CVE-2018-1000077 CVE-2018-1000078 CVE-2018-1000079 rubygems: various flaws [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1547431 [ 2 ] Bug #1528226 - CVE-2017-17790 ruby: Command injection in lib/resolv.rb:lazy_initialize() allows arbitrary code execution [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1528226 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade ruby' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be foundat -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.