Ubuntu Security Update USN-6838-2: Ruby vulnerability

LinuxBot

Member
Joined
Apr 25, 2017
Messages
5,837
Reaction score
74
Credits
-1,257
USN-6838-1 fixed CVE-2024-27281 in Ruby 2.7, Ruby 3.0, Ruby 3.1, and Ruby 3.2. This update provides the corresponding updates for Ruby 2.3 and Ruby 2.5. Original advisory details: It was discovered that Ruby RDoc incorrectly parsed certain YAML files. If a user or automated system were tricked into parsing a specially crafted .rdoc_options file, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2024-27281)

Continue reading...
 


Follow Linux.org

Staff online

Members online


Top