Lucene search

K
oraclelinuxOracleLinuxELSA-2024-1431
HistoryMar 20, 2024 - 12:00 a.m.

ruby:3.1 security, bug fix, and enhancement update

2024-03-2000:00:00
linux.oracle.com
19
ruby 3.1.4
security update
bug fixes
enhancements
http response splitting
redos vulnerability
rdoc soft dependency
ssl related test failure
fedora commit

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

EPSS

0.005

Percentile

77.3%

ruby
[3.1.4-142]

  • Upgrade to Ruby 3.1.4.
    Resolves: RHEL-28565
  • Fix HTTP response splitting in CGI.
    Resolves: RHEL-28564
  • Fix ReDos vulnerability in URI.
    Resolves: RHEL-28567
    Resolves: RHEL-28576
  • Fix ReDos vulnerability in Time.
    Resolves: RHEL-28566
  • Make RDoc soft dependency in IRB.
    Resolves: RHEL-28569
    rubygem-abrt
    [0.4.0-1]
  • Update to abrt 0.4.0.
    Resolves: rhbz#1842476
    rubygem-mysql2
    [0.5.3-3]
  • Fix SSL related test failure by backporting Fedora commit
    .
    Related: RHEL-28565
    rubygem-pg
    [1.3.2-1]
  • Update to pg 1.3.2 by merging Fedora rawhide branch (commit: 39bbd1b)
    Resolves: rhbz#2063772

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

7.3

Confidence

Low

EPSS

0.005

Percentile

77.3%