[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250770

 
 

909

 
 

196157

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

DSA-4721-1 ruby2.5 -- ruby2.5

ID: oval:org.secpod.oval:def:604918Date: (C)2020-07-10   (M)2024-01-29
Class: PATCHFamily: unix




Several vulnerabilities have been discovered in the interpreter for the Ruby language. CVE-2020-10663 Jeremy Evans reported an unsafe object creation vulnerability in the json gem bundled with Ruby. When parsing certain JSON documents, the json gem can be coerced into creating arbitrary objects in the target system. CVE-2020-10933 Samuel Williams reported a flaw in the socket library which may lead to exposure of possibly sensitive data from the interpreter.

Platform:
Debian 10.x
Product:
ruby2.5
libruby2.5
Reference:
DSA-4721-1
CVE-2020-10663
CVE-2020-10933
CVE    2
CVE-2020-10933
CVE-2020-10663
CPE    4
cpe:/o:debian:debian_linux:10.x
cpe:/a:ruby-lang:ruby:2.5
cpe:/a:ruby-lang:ruby
cpe:/o:debian:debian_linux:8.0
...

© SecPod Technologies