elsa-2024-6784
oracle_linux
Description
ruby [3.3.5-3] - Upgrade to Ruby 3.3.5 Resolves: RHEL-55409 - Fix DoS vulnerability in rexml. (CVE-2024-39908) (CVE-2024-41946) (CVE-2024-43398) Resolves: RHEL-57049 Resolves: RHEL-57054 Resolves: RHEL-57069 - Fix REXML DoS when parsing an XML having many specific characters such as whitespace character, ] and ]. (CVE-2024-41123) Resolves: RHEL-52783 rubygem-abrt [0.4.0-1] - Update to abrt 0.4.0. Resolves: rhbz#1842476 rubygem-mysql2 [0.5.5-1] - Upgrade to mysql2 0.5.5. Related: RHEL-17090 rubygem-pg [1.5.4-1] - Upgrade to pg 1.5.4. Related: RHEL-17090
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
References
No references available.
Linked Vulnerabilities
No linked vulnerabilities found.
{
"cves": [
"CVE-2024-39908",
"CVE-2024-41123",
"CVE-2024-41946",
"CVE-2024-43398"
],
"cvss": 0.0,
"database_specific": {
"severity": "MODERATE"
},
"description": "ruby\n[3.3.5-3]\n- Upgrade to Ruby 3.3.5\n Resolves: RHEL-55409\n- Fix DoS vulnerability in rexml.\n (CVE-2024-39908)\n (CVE-2024-41946)\n (CVE-2024-43398)\n Resolves: RHEL-57049\n Resolves: RHEL-57054\n Resolves: RHEL-57069\n- Fix REXML DoS when parsing an XML having many specific characters such as\n whitespace character, ] and ].\n (CVE-2024-41123)\n Resolves: RHEL-52783\n\nrubygem-abrt\n[0.4.0-1]\n- Update to abrt 0.4.0.\n Resolves: rhbz#1842476\n\nrubygem-mysql2\n[0.5.5-1]\n- Upgrade to mysql2 0.5.5.\n Related: RHEL-17090\n\nrubygem-pg\n[1.5.4-1]\n- Upgrade to pg 1.5.4.\n Related: RHEL-17090",
"id": "ELSA-2024-6784",
"ovalId": "oval:com.oracle.elsa:def:20246784",
"source": "oracle_linux",
"title": "ELSA-2024-6784: ruby:3.3 security update (MODERATE)",
"url": "https://linux.oracle.com/errata/ELSA-2024-6784.html"
}