stable

ruby-2.3.4-64.fc25

FEDORA-2017-e136d63c99 created by vondruch 7 years ago for Fedora 25
  • Fix ANSI escape sequence vulnerability (CVE-2017-0899).
  • Fix DoS vulnerability in the query command (CVE-2017-0900).
  • Fix a vulnerability in the gem installer that allowed a malicious gem to overwrite arbitrary files (CVE-2017-0901).
  • Fix DNS request hijacking vulnerability (CVE-2017-0902).
  • Fix arbitrary heap exposure during a JSON.generate call (CVE-2017-14064).

How to install

Updates may require up to 24 hours to propagate to mirrors. If the following command doesn't work, please retry later:

sudo dnf upgrade --refresh --advisory=FEDORA-2017-e136d63c99

This update has been submitted for testing by vondruch.

7 years ago

vondruch edited this update.

7 years ago

This update has been pushed to testing.

7 years ago

This update has reached 7 days in testing and can be pushed to stable now if the maintainer wishes

7 years ago

This update has been submitted for stable by vondruch.

7 years ago

This update has been pushed to stable.

7 years ago

Please login to add feedback.

Metadata
Type
security
Karma
0
Signed
Content Type
RPM
Test Gating
Settings
Unstable by Karma
-3
Stable by Karma
3
Stable by Time
disabled
Dates
submitted
7 years ago
in testing
7 years ago
in stable
7 years ago
modified
7 years ago
BZ#1487552 CVE-2017-14064 ruby: Arbitrary heap exposure during a JSON.generate call
0
0
BZ#1487553 CVE-2017-14064 ruby: Arbitrary heap exposure during a JSON.generate call [fedora-all]
0
0
BZ#1487587 CVE-2017-0901 rubygems: Arbitrary file overwrite due to incorrect validation of specification name
0
0
BZ#1487588 CVE-2017-0900 rubygems: No size limit in summary length of gem spec
0
0
BZ#1487589 CVE-2017-0902 rubygems: DNS hijacking vulnerability
0
0
BZ#1487590 CVE-2017-0899 rubygems: Escape sequence in the "summary" field of gemspec
0
0
BZ#1487591 CVE-2017-0899 CVE-2017-0900 CVE-2017-0901 CVE-2017-0902 rubygems: various flaws [fedora-all]
0
0

Automated Test Results