{"cves":["CVE-2024-41123","CVE-2024-41946","CVE-2024-43398","CVE-2024-39908"],"cvss":0.0,"database_specific":{"severity":"MODERATE"},"description":"ruby\n[3.3.5-3]\n- Upgrade to Ruby 3.3.5\n  Resolves: RHEL-57576\n- Fix DoS vulnerability in rexml.\n  (CVE-2024-39908)\n  (CVE-2024-41946)\n  (CVE-2024-43398)\n  Resolves: RHEL-57573\n  Resolves: RHEL-57570\n  Resolves: RHEL-57578\n- Fix REXML DoS when parsing an XML having many specific characters such as\n  whitespace character, ] and ].\n  (CVE-2024-41123)\n  Resolves: RHEL-57567\n- Fix incorrect symlink for rubygem-irb's library.\n  Resolves: RHEL-57597\n\n[3.3.1-2]\n- Upgrade to Ruby 3.3.1.\n  Resolves: RHEL-37697\n- Fix buffer overread vulnerability in StringIO.\n  (CVE-2024-27280)\n  Resolves: RHEL-37699\n- Fix RCE vulnerability with .rdoc_options in RDoc.\n  (CVE-2024-27281)\n  Resolves: RHEL-37696\n- Fix Arbitrary memory address read vulnerability with Regex search.\n  (CVE-2024-27282)\n  Resolves: RHEL-37698\n\n[3.3.0-1]\n- Upgrade to Ruby 3.3.0.\n  Resolves: RHEL-17089\n\n[3.1.2-142]\n- Bypass git submodule test failure on Git = 2.38.1.\n- Fix tests with Europe/Amsterdam pre-1970 time on tzdata version 2022b.\n- Fix for tzdata-2022g.\n- Fix OpenSSL.fips_mode and OpenSSL::PKey.read in OpenSSL 3 FIPS.\n  Resolves: RHEL-5590\n- ssl: use ffdhe2048 from RFC 7919 as the default DH group parameters\n  Related: RHEL-5590\n- Disable fiddle tests that use FFI closures.\n  Related: RHEL-5590\n\nrubygem-mysql2\n[0.5.5-1]\n- Upgrade to mysql2 0.5.5.\n  Related: RHEL-17089\n\nrubygem-pg\n[1.5.4-1]\n- Upgrade to pg 1.5.4.\n  Related: RHEL-17089","id":"ELSA-2024-6785","ovalId":"oval:com.oracle.elsa:def:20246785","source":"oracle_linux","title":"ELSA-2024-6785:  ruby:3.3 security update (MODERATE)","url":"https://linux.oracle.com/errata/ELSA-2024-6785.html"}