Oval Definition:oval:com.redhat.rhsa:def:20191235
Revision Date:2019-05-15Version:636
Title:RHSA-2019:1235: ruby security update (Important)
Description:Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.

Security Fix(es):

  • rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324)

  • rubygems: Escape sequence injection vulnerability in gem owner (CVE-2019-8322)

  • rubygems: Escape sequence injection vulnerability in API response handling (CVE-2019-8323)

  • rubygems: Escape sequence injection vulnerability in errors (CVE-2019-8325)

    For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2019-8321
    CVE-2019-8322
    CVE-2019-8323
    CVE-2019-8324
    CVE-2019-8325
    RHSA-2019:1235
    RHSA-2019:1235-01
    Platform(s):Red Hat Enterprise Linux 7
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 7 is installed
  • AND
  • ruby is earlier than 0:2.0.0.648-35.el7_6
  • AND ruby is signed with Red Hat redhatrelease2 key
  • ruby-devel is earlier than 0:2.0.0.648-35.el7_6
  • AND ruby-devel is signed with Red Hat redhatrelease2 key
  • ruby-doc is earlier than 0:2.0.0.648-35.el7_6
  • AND ruby-doc is signed with Red Hat redhatrelease2 key
  • ruby-irb is earlier than 0:2.0.0.648-35.el7_6
  • AND ruby-irb is signed with Red Hat redhatrelease2 key
  • ruby-libs is earlier than 0:2.0.0.648-35.el7_6
  • AND ruby-libs is signed with Red Hat redhatrelease2 key
  • ruby-tcltk is earlier than 0:2.0.0.648-35.el7_6
  • AND ruby-tcltk is signed with Red Hat redhatrelease2 key
  • rubygem-bigdecimal is earlier than 0:1.2.0-35.el7_6
  • AND rubygem-bigdecimal is signed with Red Hat redhatrelease2 key
  • rubygem-io-console is earlier than 0:0.4.2-35.el7_6
  • AND rubygem-io-console is signed with Red Hat redhatrelease2 key
  • rubygem-json is earlier than 0:1.7.7-35.el7_6
  • AND rubygem-json is signed with Red Hat redhatrelease2 key
  • rubygem-minitest is earlier than 0:4.3.2-35.el7_6
  • AND rubygem-minitest is signed with Red Hat redhatrelease2 key
  • rubygem-psych is earlier than 0:2.0.0-35.el7_6
  • AND rubygem-psych is signed with Red Hat redhatrelease2 key
  • rubygem-rake is earlier than 0:0.9.6-35.el7_6
  • AND rubygem-rake is signed with Red Hat redhatrelease2 key
  • rubygem-rdoc is earlier than 0:4.0.0-35.el7_6
  • AND rubygem-rdoc is signed with Red Hat redhatrelease2 key
  • rubygems is earlier than 0:2.0.14.1-35.el7_6
  • AND rubygems is signed with Red Hat redhatrelease2 key
  • rubygems-devel is earlier than 0:2.0.14.1-35.el7_6
  • AND rubygems-devel is signed with Red Hat redhatrelease2 key
  • BACK