Lucene search

K
redhatRedHatRHSA-2024:3546
HistoryJun 03, 2024 - 6:57 a.m.

(RHSA-2024:3546) Moderate: ruby:3.1 security, bug fix, and enhancement update

2024-06-0306:57:31
access.redhat.com
19
ruby
security update
rce
buffer overread
regex vulnerability
red hat enterprise linux 8.10

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

5.7

Confidence

Low

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.

Security Fix(es):

  • ruby: RCE vulnerability with .rdoc_options in RDoc (CVE-2024-27281)
  • ruby: Buffer overread vulnerability in StringIO (CVE-2024-27280)
  • ruby: Arbitrary memory address read vulnerability with Regex search (CVE-2024-27282)

For detailed information on changes in this release, see the Red Hat Enterprise Linux 8.10 Release Notes linked from the References section.

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

5.7

Confidence

Low