ELSA-2019-1235

ELSA-2019-1235 - ruby security update

Type:SECURITY
Impact:IMPORTANT
Release Date:2019-05-16

Description


[2.0.0.648-35]
- Introduce method as precondition to fix
CVE-2019-8321.
* rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
- Fix escape sequence injection vulnerability in API response handling.
- Prohibit arbitrary code execution when installing a malicious gem.
- Fix escape sequence injection vulnerability in errors.
* ruby-2.4.6-Applied-security-patches-for-RubyGems.patch
Resolves: rhbz#1699283

[2.0.0.648-35]
- Refresh expired certificates.


Related CVEs


CVE-2019-8324
CVE-2019-8322
CVE-2019-8323
CVE-2019-8325

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 7 (aarch64) ruby-2.0.0.648-35.el7_6.src.rpm68b444956df8fc2b60ba3eff228d093e43ae1d7ba24f2662f0bcaded79c21b86ELBA-2022-1200ol7_aarch64_latest
ruby-2.0.0.648-35.el7_6.src.rpm68b444956df8fc2b60ba3eff228d093e43ae1d7ba24f2662f0bcaded79c21b86ELBA-2022-1200ol7_aarch64_optional_latest
ruby-2.0.0.648-35.el7_6.aarch64.rpm25268b9d8bc53f07fb67e23d821925e120279662ce12ad89d44d32d4c59c781fELBA-2022-1200ol7_aarch64_latest
ruby-devel-2.0.0.648-35.el7_6.aarch64.rpm29dff1c39f96ce97d3a46c2a25b5acb11c31013ef073a1d5e4ad74aa3d72275eELBA-2022-1200ol7_aarch64_optional_latest
ruby-doc-2.0.0.648-35.el7_6.noarch.rpma1cfdf68bb1076d9865014b5b2effd2a0b272cd6c2b796687824af3d4f7ab076ELBA-2022-1200ol7_aarch64_optional_latest
ruby-irb-2.0.0.648-35.el7_6.noarch.rpm7b715aece2e78873ec952b08b45a3f3e31eece0c7891841e82567d28d6f3efecELBA-2022-1200ol7_aarch64_latest
ruby-libs-2.0.0.648-35.el7_6.aarch64.rpmbe7f4fbe269264faa3802215f1f2aa92abaf719e6dcb79e090948089ea410324ELBA-2022-1200ol7_aarch64_latest
ruby-tcltk-2.0.0.648-35.el7_6.aarch64.rpm930c5bb749ab1e70877e129fdc8660451aa65a349710de5266cfbf7c4bfcdfaeELBA-2022-1200ol7_aarch64_optional_latest
rubygem-bigdecimal-1.2.0-35.el7_6.aarch64.rpm95762815db271d12723d3bf7edfd0ea226344ef42c53491ec63af6e42e51520bELBA-2022-1200ol7_aarch64_latest
rubygem-io-console-0.4.2-35.el7_6.aarch64.rpm1172d1fdccd034a32e44807f99578543d929021db669f79ea1aee16767a60186ELBA-2022-1200ol7_aarch64_latest
rubygem-json-1.7.7-35.el7_6.aarch64.rpmb01f62acb0a826ec561058c6b354f87e0e8452f83e8edb29212d0edae60bcef6ELBA-2022-1200ol7_aarch64_latest
rubygem-minitest-4.3.2-35.el7_6.noarch.rpm6eae21727576749ba82d183af276773786f760e2e789188882d4dc1366e87b7cELBA-2022-1200ol7_aarch64_optional_latest
rubygem-psych-2.0.0-35.el7_6.aarch64.rpm4752d65a8eaef1b5609d0784e730d5b979547861f4ab6c58d68b873e61cb5183ELBA-2022-1200ol7_aarch64_latest
rubygem-rake-0.9.6-35.el7_6.noarch.rpmc5ecd2be9ac06eedd6c2d8c2a5040348ce0d85c0fee084053fbe55f3431cbc39ELBA-2022-1200ol7_aarch64_optional_latest
rubygem-rdoc-4.0.0-35.el7_6.noarch.rpmb7f7e3b5855a1706cb761d3fa6031f8c8f6038941cf883e15b574aefa2744957ELBA-2022-1200ol7_aarch64_latest
rubygems-2.0.14.1-35.el7_6.noarch.rpm2a2482f61cf6eda1504e4134e65bcc4041be919651857f631b3b1fef6f254481ELBA-2022-1200ol7_aarch64_latest
rubygems-devel-2.0.14.1-35.el7_6.noarch.rpmd5449cc76053658c5f02b6f5d0c78b1a68c1602ce231ffcdd8892b12331acd47ELBA-2022-1200ol7_aarch64_optional_latest
Oracle Linux 7 (x86_64) ruby-2.0.0.648-35.el7_6.src.rpm68b444956df8fc2b60ba3eff228d093e43ae1d7ba24f2662f0bcaded79c21b86ELBA-2022-1200ol7_x86_64_latest
ruby-2.0.0.648-35.el7_6.src.rpm68b444956df8fc2b60ba3eff228d093e43ae1d7ba24f2662f0bcaded79c21b86ELBA-2022-1200ol7_x86_64_optional_latest
ruby-2.0.0.648-35.el7_6.src.rpm68b444956df8fc2b60ba3eff228d093e43ae1d7ba24f2662f0bcaded79c21b86ELBA-2022-1200ol7_x86_64_u6_patch
ruby-2.0.0.648-35.el7_6.x86_64.rpm40542dbd848b79a62122b94fc631611af223bbcd1d461fe5757fd14d8b1bc9efELBA-2022-1200ol7_x86_64_latest
ruby-2.0.0.648-35.el7_6.x86_64.rpm40542dbd848b79a62122b94fc631611af223bbcd1d461fe5757fd14d8b1bc9efELBA-2022-1200ol7_x86_64_u6_patch
ruby-devel-2.0.0.648-35.el7_6.x86_64.rpmf419d60903a19ac66c7cb12710f847729f692cfd4402f6b7f2efbe28a57c7b47ELBA-2022-1200ol7_x86_64_optional_latest
ruby-doc-2.0.0.648-35.el7_6.noarch.rpma1cfdf68bb1076d9865014b5b2effd2a0b272cd6c2b796687824af3d4f7ab076ELBA-2022-1200ol7_x86_64_optional_latest
ruby-irb-2.0.0.648-35.el7_6.noarch.rpm7b715aece2e78873ec952b08b45a3f3e31eece0c7891841e82567d28d6f3efecELBA-2022-1200ol7_x86_64_latest
ruby-irb-2.0.0.648-35.el7_6.noarch.rpm7b715aece2e78873ec952b08b45a3f3e31eece0c7891841e82567d28d6f3efecELBA-2022-1200ol7_x86_64_u6_patch
ruby-libs-2.0.0.648-35.el7_6.i686.rpm454ff124fbf8ee565791cce9876b48bd697e2d26e91d0eb9a18fb8c439b01d15ELBA-2022-1200ol7_x86_64_latest
ruby-libs-2.0.0.648-35.el7_6.i686.rpm454ff124fbf8ee565791cce9876b48bd697e2d26e91d0eb9a18fb8c439b01d15ELBA-2022-1200ol7_x86_64_u6_patch
ruby-libs-2.0.0.648-35.el7_6.x86_64.rpm720381168aaa90e3be1ed753776d952674bc699b041fd38ecd109c42a0729890ELBA-2022-1200ol7_x86_64_latest
ruby-libs-2.0.0.648-35.el7_6.x86_64.rpm720381168aaa90e3be1ed753776d952674bc699b041fd38ecd109c42a0729890ELBA-2022-1200ol7_x86_64_u6_patch
ruby-tcltk-2.0.0.648-35.el7_6.x86_64.rpmd5cd20172abfa8fd8b7805f77b59beea276448904a28c96f34d3e9e4c8d0023bELBA-2022-1200ol7_x86_64_optional_latest
rubygem-bigdecimal-1.2.0-35.el7_6.x86_64.rpmeadec1fb22b5ea8e8400e1a8e1a18c961854b9532080e6c5b3d767a66b4d232cELBA-2022-1200ol7_x86_64_latest
rubygem-bigdecimal-1.2.0-35.el7_6.x86_64.rpmeadec1fb22b5ea8e8400e1a8e1a18c961854b9532080e6c5b3d767a66b4d232cELBA-2022-1200ol7_x86_64_u6_patch
rubygem-io-console-0.4.2-35.el7_6.x86_64.rpm103e1e12726a76d6a16a93ebbe1e76efbe52a8578a72ca2e0731edf39fc30721ELBA-2022-1200ol7_x86_64_latest
rubygem-io-console-0.4.2-35.el7_6.x86_64.rpm103e1e12726a76d6a16a93ebbe1e76efbe52a8578a72ca2e0731edf39fc30721ELBA-2022-1200ol7_x86_64_u6_patch
rubygem-json-1.7.7-35.el7_6.x86_64.rpm8ce8d76b6d8295cc93a730645830216de945f5260505d72cc8a774895d1914e6ELBA-2022-1200ol7_x86_64_latest
rubygem-json-1.7.7-35.el7_6.x86_64.rpm8ce8d76b6d8295cc93a730645830216de945f5260505d72cc8a774895d1914e6ELBA-2022-1200ol7_x86_64_u6_patch
rubygem-minitest-4.3.2-35.el7_6.noarch.rpm6eae21727576749ba82d183af276773786f760e2e789188882d4dc1366e87b7cELBA-2022-1200ol7_x86_64_optional_latest
rubygem-psych-2.0.0-35.el7_6.x86_64.rpm56914aa123c5ac2aef5eeaf26ca4f6c65921e1422c6f894d592d82ac10f3b701ELBA-2022-1200ol7_x86_64_latest
rubygem-psych-2.0.0-35.el7_6.x86_64.rpm56914aa123c5ac2aef5eeaf26ca4f6c65921e1422c6f894d592d82ac10f3b701ELBA-2022-1200ol7_x86_64_u6_patch
rubygem-rake-0.9.6-35.el7_6.noarch.rpmc5ecd2be9ac06eedd6c2d8c2a5040348ce0d85c0fee084053fbe55f3431cbc39ELBA-2022-1200ol7_x86_64_optional_latest
rubygem-rdoc-4.0.0-35.el7_6.noarch.rpmb7f7e3b5855a1706cb761d3fa6031f8c8f6038941cf883e15b574aefa2744957ELBA-2022-1200ol7_x86_64_latest
rubygem-rdoc-4.0.0-35.el7_6.noarch.rpmb7f7e3b5855a1706cb761d3fa6031f8c8f6038941cf883e15b574aefa2744957ELBA-2022-1200ol7_x86_64_u6_patch
rubygems-2.0.14.1-35.el7_6.noarch.rpm2a2482f61cf6eda1504e4134e65bcc4041be919651857f631b3b1fef6f254481ELBA-2022-1200ol7_x86_64_latest
rubygems-2.0.14.1-35.el7_6.noarch.rpm2a2482f61cf6eda1504e4134e65bcc4041be919651857f631b3b1fef6f254481ELBA-2022-1200ol7_x86_64_u6_patch
rubygems-devel-2.0.14.1-35.el7_6.noarch.rpmd5449cc76053658c5f02b6f5d0c78b1a68c1602ce231ffcdd8892b12331acd47ELBA-2022-1200ol7_x86_64_optional_latest



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete