In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj (CVE-2017-15928). Also, the package was broken and has been fixed to function properly. . MGASA-2019-0123 - Updated ruby-ox packages fix security vulnerability Publication date: 05 Apr 2019 URL: https://advisories.mageia.org/MGASA-2019-0123.html Type: security Affected Mageia releases: 6 CVE: CVE-2017-15928 In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj (CVE-2017-15928). Also, the package was broken and has been fixed to function properly. References: - https://bugs.mageia.org/show_bug.cgi?id=22050 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.