Ubuntu security notices
USN-3528-1: Ruby vulnerabilities
USN-3528-1: Ruby vulnerabilities Ubuntu Security Notice USN-3528-1 10th January, 2018 ruby1.9.1, ruby2.3 vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: Ubuntu 17.10 Ubuntu 16.04 LTS Ubuntu 14.04 LTS Summary Several security issues were fixed in Ruby. Software description ruby1.9.1 – Interpreter of object-oriented scripting language Ruby ruby2.3 – Interpreter of object-oriented scripting language Ruby Details It was discovered that Ruby incorrectly handled certain terminal emulatorescape sequences. An attacker could use this to execute arbitrary code viaa crafted user name. This issue only affected Ubuntu 16.04 LTS and Ubuntu 17.10.(CVE-2017-10784) It was discovered that Ruby incorrectly handled certain strings.An attacker could use this to cause a denial of service. This issueonly affected Ubuntu 16.04 LTS and Ubuntu 17.10. (CVE-2017-14033) It was discovered that Ruby incorrectly handled some generating JSON.An attacker could use this to possible expose sensitive [ more… ]