[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248430

 
 

909

 
 

195407

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ELSA-2019-2028 -- Oracle ruby

ID: oval:org.secpod.oval:def:1504304Date: (C)2021-01-10   (M)2024-01-29
Class: PATCHFamily: unix




[2.0.0.648-36] - Introduce "Gem::UserInteraction#verbose" method as precondition to fix CVE-2019-8321. * rubygems-2.3.0-refactor-checking-really_verbose.patch - Fix escape sequence injection vulnerability in verbose. - Fix escape sequence injection vulnerability in gem owner. Resolves: CVE-2019-8322 - Fix escape sequence injection vulnerability in API response handling. Resolves: CVE-2019-8323 - Prohibit arbitrary code execution when installing a malicious gem. Resolves: CVE-2019-8324 - Fix escape sequence injection vulnerability in errors. Resolves: CVE-2019-8325 * ruby-2.4.6-Applied-security-patches-for-RubyGems.patch

Platform:
Oracle Linux 7
Product:
ruby
Reference:
ELSA-2019-2028
CVE-2017-17742
CVE-2018-1000077
CVE-2018-6914
CVE-2018-1000073
CVE-2018-1000074
CVE-2018-1000076
CVE-2018-8778
CVE-2018-8780
CVE-2018-16396
CVE-2018-1000079
CVE-2018-8777
CVE-2018-1000078
CVE-2018-8779
CVE-2018-1000075
CVE    14
CVE-2018-1000079
CVE-2018-1000077
CVE-2018-1000078
CVE-2018-1000075
...

© SecPod Technologies