Red Hat CloudForms Management Engine delivers the insight, control, and automation needed to address the challenges of managing virtual environments. CloudForms Management Engine is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components.
Security Fix(es):
rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324)
rubygems: Delete directory using symlink when decompressing tar (CVE-2019-8320)
rubygems: Escape sequence injection vulnerability in verbose (CVE-2019-8321)
rubygems: Escape sequence injection vulnerability in gem owner (CVE-2019-8322)
rubygems: Escape sequence injection vulnerability in API response handling (CVE-2019-8323)
rubygems: Escape sequence injection vulnerability in errors (CVE-2019-8325)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Additional Changes:
This update fixes various bugs and adds enhancements. Documentation for these changes is available from the Release Notes document linked to in the References section.
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
RedHat | 7 | noarch | rubygem-rdoc | < 5.0.0-91.el7cf | rubygem-rdoc-5.0.0-91.el7cf.noarch.rpm |
RedHat | 7 | x86_64 | rubygem-did_you_mean | < 1.1.0-91.el7cf | rubygem-did_you_mean-1.1.0-91.el7cf.x86_64.rpm |
RedHat | 7 | x86_64 | rubygem-net-telnet | < 0.1.1-91.el7cf | rubygem-net-telnet-0.1.1-91.el7cf.x86_64.rpm |
RedHat | 7 | noarch | ruby-irb | < 2.4.6-91.el7cf | ruby-irb-2.4.6-91.el7cf.noarch.rpm |
RedHat | 7 | x86_64 | cfme-appliance-common | < 5.10.5.1-1.el7cf | cfme-appliance-common-5.10.5.1-1.el7cf.x86_64.rpm |
RedHat | 7 | x86_64 | cfme-amazon-smartstate | < 5.10.5.1-1.el7cf | cfme-amazon-smartstate-5.10.5.1-1.el7cf.x86_64.rpm |
RedHat | 7 | x86_64 | cfme-appliance | < 5.10.5.1-1.el7cf | cfme-appliance-5.10.5.1-1.el7cf.x86_64.rpm |
RedHat | 7 | noarch | rubygem-xmlrpc | < 0.2.1-91.el7cf | rubygem-xmlrpc-0.2.1-91.el7cf.noarch.rpm |
RedHat | 7 | noarch | rubygem-test-unit | < 3.2.3-91.el7cf | rubygem-test-unit-3.2.3-91.el7cf.noarch.rpm |
RedHat | 7 | noarch | rubygems-devel | < 2.6.14.4-91.el7cf | rubygems-devel-2.6.14.4-91.el7cf.noarch.rpm |