ELSA-2019-1235

ELSA-2019-1235 - ruby security update

Type:SECURITY
Severity:IMPORTANT
Release Date:2019-05-16

Description


[2.0.0.648-35]
- Introduce method as precondition to fix
CVE-2019-8321.
* rubygems-2.3.0-refactor-checking-really_verbose.patch
- Fix escape sequence injection vulnerability in verbose.
- Fix escape sequence injection vulnerability in gem owner.
- Fix escape sequence injection vulnerability in API response handling.
- Prohibit arbitrary code execution when installing a malicious gem.
- Fix escape sequence injection vulnerability in errors.
* ruby-2.4.6-Applied-security-patches-for-RubyGems.patch
Resolves: rhbz#1699283

[2.0.0.648-35]
- Refresh expired certificates.


Related CVEs


CVE-2019-8322
CVE-2019-8323
CVE-2019-8324
CVE-2019-8325

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 7 (aarch64) ruby-2.0.0.648-35.el7_6.src.rpmf7843260eaae5e57327f3450c1ee4707ELSA-2019-2028
ruby-2.0.0.648-35.el7_6.aarch64.rpmdca2818c452ef820482366f99de5b998ELSA-2019-2028
ruby-devel-2.0.0.648-35.el7_6.aarch64.rpm6ec00be89e52c5a18cefa112adf0f761ELSA-2019-2028
ruby-doc-2.0.0.648-35.el7_6.noarch.rpm54fe7b07baa17b270f8ec47964f91f67ELSA-2019-2028
ruby-irb-2.0.0.648-35.el7_6.noarch.rpm04e71794fa5e41244883dcdb6b0a6546ELSA-2019-2028
ruby-libs-2.0.0.648-35.el7_6.aarch64.rpm41704757fafdc85cd12fcd577d85b37dELSA-2019-2028
ruby-tcltk-2.0.0.648-35.el7_6.aarch64.rpm8ac215c7be14119e1f7b8592a050ce5bELSA-2019-2028
rubygem-bigdecimal-1.2.0-35.el7_6.aarch64.rpmc46b46ded9ec3a778aec30b6e7dd13c0ELSA-2019-2028
rubygem-io-console-0.4.2-35.el7_6.aarch64.rpmc67b9d493909558a756642a7cf2e4122ELSA-2019-2028
rubygem-json-1.7.7-35.el7_6.aarch64.rpmbe850949413b52fb9e07c673c9f41359ELSA-2019-2028
rubygem-minitest-4.3.2-35.el7_6.noarch.rpm037fefe75c42221176ef7c01ddaaaab2ELSA-2019-2028
rubygem-psych-2.0.0-35.el7_6.aarch64.rpma27536b5d7425938517d01c9a85c0c43ELSA-2019-2028
rubygem-rake-0.9.6-35.el7_6.noarch.rpmc23f136974766334b8a56afb46098b9aELSA-2019-2028
rubygem-rdoc-4.0.0-35.el7_6.noarch.rpm8fe3307731cca7a1920cebfd6ae95cfcELSA-2019-2028
rubygems-2.0.14.1-35.el7_6.noarch.rpmfd31b38161779a734cced5a419dea111ELSA-2019-2028
rubygems-devel-2.0.14.1-35.el7_6.noarch.rpme5486df24fb5025e5fe2fc9c768e9562ELSA-2019-2028
Oracle Linux 7 (x86_64) ruby-2.0.0.648-35.el7_6.src.rpmf7843260eaae5e57327f3450c1ee4707ELSA-2019-2028
ruby-2.0.0.648-35.el7_6.x86_64.rpm1ae6cf43d5d5092ffbb7e45919aee4fdELSA-2019-2028
ruby-devel-2.0.0.648-35.el7_6.x86_64.rpmbac69a4d4b4b8da5eb7722837713e040ELSA-2019-2028
ruby-doc-2.0.0.648-35.el7_6.noarch.rpm54fe7b07baa17b270f8ec47964f91f67ELSA-2019-2028
ruby-irb-2.0.0.648-35.el7_6.noarch.rpm04e71794fa5e41244883dcdb6b0a6546ELSA-2019-2028
ruby-libs-2.0.0.648-35.el7_6.i686.rpmda96cfe6eefa3fb17780dfbb41cd942eELSA-2019-2028
ruby-libs-2.0.0.648-35.el7_6.x86_64.rpm5f3a68ee1aa705ec01f8c1bc07909616ELSA-2019-2028
ruby-tcltk-2.0.0.648-35.el7_6.x86_64.rpme195429c7792658df3bf1dab9415f089ELSA-2019-2028
rubygem-bigdecimal-1.2.0-35.el7_6.x86_64.rpme583c6b7e4f24512f1c9a73515928aa4ELSA-2019-2028
rubygem-io-console-0.4.2-35.el7_6.x86_64.rpm522757d013361acfa9c646e429426e78ELSA-2019-2028
rubygem-json-1.7.7-35.el7_6.x86_64.rpm6a394d8ffb7906303cff26773e1b3627ELSA-2019-2028
rubygem-minitest-4.3.2-35.el7_6.noarch.rpm037fefe75c42221176ef7c01ddaaaab2ELSA-2019-2028
rubygem-psych-2.0.0-35.el7_6.x86_64.rpma22981ecb646bae91501e915d8b2b799ELSA-2019-2028
rubygem-rake-0.9.6-35.el7_6.noarch.rpmc23f136974766334b8a56afb46098b9aELSA-2019-2028
rubygem-rdoc-4.0.0-35.el7_6.noarch.rpm8fe3307731cca7a1920cebfd6ae95cfcELSA-2019-2028
rubygems-2.0.14.1-35.el7_6.noarch.rpmfd31b38161779a734cced5a419dea111ELSA-2019-2028
rubygems-devel-2.0.14.1-35.el7_6.noarch.rpme5486df24fb5025e5fe2fc9c768e9562ELSA-2019-2028



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete