• Ruby vulnerabilities

    From bugz_ubuntu@21:4/110 to Ubuntu Users on Tue Nov 26 17:10:10 2019
    ruby2.3, ruby2.5 vulnerabilities

    A security issue affects these releases of Ubuntu and its
    derivatives:

    * Ubuntu 19.10
    * Ubuntu 19.04
    * Ubuntu 18.04 LTS
    * Ubuntu 16.04 LTS

    Summary

    Several security issues were fixed in Ruby.

    Software Description

    * ruby2.5 - Interpreter of object-oriented scripting language
    Ruby
    * ruby2.3 - Object-oriented scripting language

    Details

    It was discovered that Ruby incorrectly handled certain files. An
    attacker could possibly use this issue to pass path matching what
    can lead to an unauthorized access. (CVE-2019-15845)

    It was discovered that Ruby incorrectly handled certain regular
    expressions. An attacker could use this issue to cause a denial of
    service. (CVE-2019-16201)

    It was discovered that Ruby incorrectly handled certain HTTP
    headers. An attacker could possibly use this issue to execute
    arbitrary code. (CVE-2019-16254)

    It was discovered that Ruby incorrectly handled certain inputs. An
    attacker could possibly use this issue to execute arbitrary code.
    (CVE-2019-16255)

    Update instructions

    The problem can be corrected by updating your system to the
    following package versions:

    Ubuntu 19.10
    libruby2.5 - 2.5.5-4ubuntu2.1
    ruby2.5 - 2.5.5-4ubuntu2.1

    Ubuntu 19.04
    libruby2.5 - 2.5.5-1ubuntu1.1
    ruby2.5 - 2.5.5-1ubuntu1.1

    Ubuntu 18.04 LTS
    libruby2.5 - 2.5.1-1ubuntu1.6
    ruby2.5 - 2.5.1-1ubuntu1.6

    Ubuntu 16.04 LTS
    libruby2.3 - 2.3.1-2~ubuntu16.04.14
    ruby2.3 - 2.3.1-2~ubuntu16.04.14

    To update your system, please follow these instructions:
    https://wiki.ubuntu.com/Security/Upgrades.

    In general, a standard system update will make all the necessary
    changes.

    References

    * CVE-2019-15845
    * CVE-2019-16201
    * CVE-2019-16254
    * CVE-2019-16255

    --- Mystic BBS v1.12 A43 (Linux/64)
    * Origin: BZ&BZ BBS (21:4/110)