USN-3945-1: Ruby vulnerabilities
USN-3945-1: Ruby vulnerabilities ruby1.9.1, ruby2.0, ruby2.3, ruby2.5 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 18.10 Ubuntu 18.04 LTS Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Ruby. Software Description ruby2.5 – Interpreter of object-oriented scripting language Ruby ruby2.3 – Object-oriented scripting language ruby1.9.1 – Object-oriented scripting language ruby2.0 – Object-oriented scripting language Details It was discovered that Ruby incorrectly handled certain RubyGems. An attacker could possibly use this issue to execute arbitrary commands. (CVE-2019-8320) It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. (CVE-2019-8321, CVE-2019-8322, CVE-2019-8323, CVE-2019-8324, CVE-2019-8325) Update instructions The problem can be corrected by updating your system to the following package versions: Ubuntu 18.10 libruby2.5 – 2.5.1-5ubuntu4.3 ruby2.5 – 2.5.1-5ubuntu4.3 Ubuntu 18.04 LTS libruby2.5 – 2.5.1-1ubuntu1.2 [ more… ]