Ubuntu Security Update USN-6181-1: Ruby vulnerabilities

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,931
Reaction score
75
Credits
-1,257
Hiroshi Tokumaru discovered that Ruby did not properly handle certain user input for applications the generate HTTP responses using cgi gem. An attacker could possibly use this issue to maliciously modify the response a user would receive from a vulnerable application. This issue only affected Ubuntu 22.10. (CVE-2021-33621) It was discovered that Ruby incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-28755, CVE-2023-28756)

Continue reading...
 


Follow Linux.org

Members online


Top