Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -4 articles for you...
172

Ubuntu 24.04 LTS: USN-7057-1 critical: WEBrick HTTP smuggling risk

WEBrick could allow a HTTP request smuggling attack.. ========================================================================== Ubuntu Security Notice USN-7057-1 October 07, 2024 ruby-webrick vulnerability ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 24.04 LTS Summary: WEBrick could allow a HTTP request smuggling attack. Software Description: - ruby-webrick: HTTP server toolkit in Ruby Details: It was discovered that WEBrick incorrectly handled having both a Content- Length header and a Transfer-Encoding header. A remote attacker could possibly use this issue to perform a HTTP request smuggling attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 24.04 LTS ruby-webrick 1.8.1-1ubuntu0.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7057-1 CVE-2024-47220 Package Information: https://launchpad.net/ubuntu/+source/ruby-webrick/1.8.1-1ubuntu0.1 . Ubuntu patches address WEBrick flaw associated with HTTP request smuggling. Seek mitigation strategies and respond promptly!. Ubuntu Security Update, WEBrick Mitigation, HTTP Attack Prevention, Ruby WEBrick Advisory. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 07, 2024 Critical Ubuntu
203

Mageia: 2020-0423 Moderate: Ruby WEBrick HTTP Request Smuggling

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to “smuggle” a request (CVE-2020-25613). . MGASA-2020-0423 - Updated ruby packages fix a security vulnerability Publication date: 13 Nov 2020 URL: https://advisories.mageia.org/MGASA-2020-0423.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-25613 A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to “smuggle” a request (CVE-2020-25613). References: - https://bugs.mageia.org/show_bug.cgi?id=27401 - https://www.ruby-lang.org/en/news/2020/09/29/http-request-smuggling-cve-2020-25613/ - https://www.cve.org/CVERecord?id=CVE-2020-25613 SRPMS: - 7/core/ruby-2.5.8-22.mga7 . Mageia 2020-0423 security fix tackles a severe HTTP request smuggling vulnerability linked to WEBrick’s management of incoming request headers.. Mageia security advisory, WEBrick update, HTTP request issue, Ruby vulnerability. . LinuxSecurity.com Team

Calendar 2 Nov 13, 2020 Mageia
197

Debian LTS: DLA-2392-1 Critical WEBrick Request Smuggling Issue

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with jruby) was too tolerant against . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2392-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta October 01, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : jruby Version : 1.7.26-1+deb9u3 CVE ID : CVE-2020-25613 A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with jruby) was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to “smuggle” a request. For Debian 9 stretch, this problem has been fixed in version 1.7.26-1+deb9u3. We recommend that you upgrade your jruby packages. For the detailed security status of jruby please refer to its security tracker page at: https://security-tracker.debian.org/tracker/source-package/jruby Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Ubuntu Security Notice USN-4304-1 resolves a critical vulnerability in OpenSSL affecting multiple distributions. Immediate patching is advised.. Debian LTS, WEBrick, jruby update, security advisory, HTTP request smuggling. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 01, 2020 Critical Debian LTS
197

Debian LTS: DLA-2391-1 ruby2.3 Critical: WEBrick HTTP Request Smuggling

A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with ruby2.3) was too tolerant against . - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2391-1 This email address is being protected from spambots. You need JavaScript enabled to view it. https://www.debian.org/lts/security/ Utkarsh Gupta October 01, 2020 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : ruby2.3 Version : 2.3.3-1+deb9u9 CVE ID : CVE-2020-25613 A potential HTTP request smuggling vulnerability in WEBrick was reported. WEBrick (bundled along with ruby2.3) was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to “smuggle” a request. For Debian 9 stretch, this problem has been fixed in version 2.3.3-1+deb9u9. We recommend that you upgrade your ruby2.3 packages. For the detailed security status of ruby2.3 please refer to its security tracker page at: Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . Update Ruby version 2.3 to remediate the HTTP request smuggling vulnerability in WEBrick, as instructed in DLA-2391-1 for users of Debian LTS.. webrick security, ruby update, request smuggling fix, debian advisory, ruby2.3 security. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 Oct 01, 2020 Critical Debian LTS
91

Gentoo: GLSA-202103-15 Critical Risk of Ruby Denial of Service

Ruby WEBrick and XMLRPC servers are vulnerable to Denial of Service.. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200605-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - https://security.gentoo.org/ - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Severity: Normal Title: Ruby: Denial of Service Date: May 10, 2006 Bugs: #130657 ID: 200605-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Synopsis ======= Ruby WEBrick and XMLRPC servers are vulnerable to Denial of Service. Background ========= Ruby is an interpreted scripting language for quick and easy object-oriented programming. It comes bundled with HTTP ("WEBrick") and XMLRPC server objects. Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-lang/ruby < 1.8.4-r1 > = 1.8.4-r1 Description ========== Ruby uses blocking sockets for WEBrick and XMLRPC servers. Impact ===== An attacker could send large amounts of data to an affected server to block the socket and thus deny other connections to the server. Workaround ========= There is no known workaround at this time. Resolution ========= All Ruby users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose "> =dev-lang/ruby-1.8.4-r1" References ========= [ 1 ] CVE-2006-1931 https://www.cve.org/CVERecord?id=CVE-2006-1931 [ 2 ] Ruby release announcement Availability =========== This GLSA and any updates to it are available for viewing at the Gentoo Security Website: https://security.gentoo.org/glsa/200605-11 Concerns? ======== Security is a primary focus of Gentoo Linux andensuring the confidentiality and security of our users machines is of utmost importance to us. Any security concerns should be addressed to This email address is being protected from spambots. You need JavaScript enabled to view it. or alternatively, you may file a bug at https://bugs.gentoo.org/. License ====== Copyright 2006 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. https://creativecommons.org/licenses/by-sa/2.5/ . Ruby WEBrick and XMLRPC servers on Gentoo face potential Denial of Service vulnerabilities. Users are advised to update their systems promptly to maintain security.. Ruby Denial of Service,Gentoo Advisory,WEBrick Threat. . Severity: Critical. LinuxSecurity.com Team

Calendar 2 May 10, 2006 Critical Gentoo
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":545,"type":"x","order":1,"pct":78.42,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.32,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.37,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here