[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-3966-1 ruby2.3 -- ruby2.3

ID: oval:org.secpod.oval:def:53129Date: (C)2019-04-04   (M)2024-01-29
Class: PATCHFamily: unix




Multiple vulnerabilities were discovered in the interpreter for the Ruby language: CVE-2015-9096 SMTP command injection in Net::SMTP. CVE-2016-7798 Incorrect handling of initialization vector in the GCM mode in the OpenSSL extension. CVE-2017-0900 Denial of service in the RubyGems client. CVE-2017-0901 Potential file overwrite in the RubyGems client. CVE-2017-0902 DNS hijacking in the RubyGems client. CVE-2017-14064 Heap memory disclosure in the JSON library.

Platform:
Linux Mint 3
Product:
ruby2.3
Reference:
DSA-3966-1
CVE-2015-9096
CVE-2016-7798
CVE-2017-0899
CVE-2017-0900
CVE-2017-0901
CVE-2017-0902
CVE-2017-14064
CVE    7
CVE-2016-7798
CVE-2017-0901
CVE-2017-0902
CVE-2017-0899
...
CPE    2
cpe:/a:ruby-lang:ruby2.3
cpe:/o:linux_mint:linux_mint:3

© SecPod Technologies