Debian Linux Security Advisory 4586-1 - Several vulnerabilities have been discovered in the interpreter for the Ruby language, which could result in unauthorized access by bypassing intended path matchings, denial of service, or the execution of arbitrary code.
89a3287a7f18397cf7ba29822602a738221673bb04079089b1021a5cfa501551
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4586-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
December 17, 2019 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : ruby2.5
CVE ID : CVE-2019-15845 CVE-2019-16201 CVE-2019-16254 CVE-2019-16255
Several vulnerabilities have been discovered in the interpreter for the
Ruby language, which could result in unauthorized access by bypassing
intended path matchings, denial of service, or the execution of
arbitrary code.
For the stable distribution (buster), these problems have been fixed in
version 2.5.5-3+deb10u1.
We recommend that you upgrade your ruby2.5 packages.
For the detailed security status of ruby2.5 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/ruby2.5
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl34oDxfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0SixA//RivjIrvziyMZKMS30716X1kgB3M1eXpL/oKCISu59wU3/dyrO4r2pwUj
fcqmZs7PQp1iFKCiRr7ZijS2V4efeK9UxmuwxRzQYNXnVhgkngbMc5j4LG56T6sG
uf1Mu2bsAOWEWBEDHLOFwoNmza12VTgBwAHMaVgl7tIdJeu1iit7Xryz5XY6xSHB
IReUiafIidLQAy5621pARmRNPhgxrwsNeSbpm3Cf8BiPcZi0pDYssJWx89JnVYU2
f9nHkHrTOPwq7vwgZlBdRFkcflRCX6V5yp3IMO0GatPy2xTZ4QFgBzATy9ES7A9y
51UrubgbvF1sf0T0NFm3l+BiCpePWSbKWIDhKPVUTQrLpNzZUhED3apNpYPe0F+/
tRcRSQ9J2bnPCE+sx5oZu7HXmNZKntyCN0blc5MtSPodLKgVXq1D4/4fFVH1J51X
BH8D3du+chM/ty5b+yL9HJIhYu0mLmr7h3fMpy8kPAjfSXi+LELtp/pFrDrFmf4S
kz1qTumC098pw57QKG+OJKOmGeT2x3wzmdOHWlkMHGh0HYHY1pSPA60P7rOw+9uR
p7clYTtu07rWsGMmwWJmBcb/YxtASagdSxD2fI50mTkZfkd7Tu3j405lcXMizsGg
IOteqeKY4g4ngrVlHxHg1hcc2QlKlUpSOQFidbBCL5EsTc8HkIc=ERNm
-----END PGP SIGNATURE-----