Several flaws have been found in ruby2.1, an interpreter of an object-oriented scripting language. . Package : ruby2.1 Version : 2.1.5-2+deb8u8 CVE ID : CVE-2019-15845 CVE-2019-16201 CVE-2019-16254 CVE-2019-16255 Several flaws have been found in ruby2.1, an interpreter of an object-oriented scripting language. CVE-2019-15845 Path matching might pass in File.fnmatch and File.fnmatch? due to a NUL character injection. CVE-2019-16201 A loop caused by a wrong regular expression could lead to a denial of service of a WEBrick service. CVE-2019-16254 This is the same issue as CVE-2017-17742, whose fix was not complete. CVE-2019-16255 Giving untrusted data to the first argument of Shell#[] and Shell#test might lead to a code injection vulnerability. For Debian 8 "Jessie", these problems have been fixed in version 2.1.5-2+deb8u8. We recommend that you upgrade your ruby2.1 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Enhance Debian 8 security by upgrading Ruby from version 2.1 to address vulnerabilities like code injection and denial-of-service attacks. Follow these steps for timely protection.. ruby2.1, security update, Debian LTS, scripting language, security flaws. . Severity: Critical. LinuxSecurity.com Team
Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627, CVE-2017-5628.. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-dc6023e849 2017-02-22 13:27:06.013938 -------------------------------------------------------------------------------- Name : mujs Product : Fedora 25 Version : 0 Release : 8.20170124git4006739.fc25 URL : https://mujs.com/ Summary : An embeddable Javascript interpreter Description : MuJS is a lightweight Javascript interpreter designed for embedding in other software to extend them with scripting capabilities. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2016-10132, CVE-2016-10133, CVE-2016-10141, CVE-2017-5627, CVE-2017-5628. -------------------------------------------------------------------------------- References: [ 1 ] Bug #1412967 - CVE-2016-10132 CVE-2016-10133 CVE-2016-10141 CVE-2017-5627 CVE-2017-5628 mujs: Multiple security issues https://bugzilla.redhat.com/show_bug.cgi?id=1412967 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade mujs' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.