Lucene search

K
oraclelinuxOracleLinuxELSA-2024-6784
HistorySep 19, 2024 - 12:00 a.m.

ruby:3.3 security update

2024-09-1900:00:00
linux.oracle.com
9
ruby
security update
upgrade
vulnerability
dos
rexml
cve-2024-39908
cve-2024-41946
cve-2024-43398
cve-2024-41123
abrt
mysql2
pg
unix

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

Low

ruby
[3.3.5-3]

  • Upgrade to Ruby 3.3.5
    Resolves: RHEL-55409
  • Fix DoS vulnerability in rexml.
    (CVE-2024-39908)
    (CVE-2024-41946)
    (CVE-2024-43398)
    Resolves: RHEL-57049
    Resolves: RHEL-57054
    Resolves: RHEL-57069
  • Fix REXML DoS when parsing an XML having many specific characters such as
    whitespace character, >] and ]>.
    (CVE-2024-41123)
    Resolves: RHEL-52783
    rubygem-abrt
    [0.4.0-1]
  • Update to abrt 0.4.0.
    Resolves: rhbz#1842476
    rubygem-mysql2
    [0.5.5-1]
  • Upgrade to mysql2 0.5.5.
    Related: RHEL-17090
    rubygem-pg
    [1.5.4-1]
  • Upgrade to pg 1.5.4.
    Related: RHEL-17090

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.4

Confidence

Low