elsa-2024-6785
oracle_linuxruby [3.3.5-3] - Upgrade to Ruby 3.3.5 Resolves: RHEL-57576 - Fix DoS vulnerability in rexml. (CVE-2024-39908) (CVE-2024-41946) (CVE-2024-43398) Resolves: RHEL-57573 Resolves: RHEL-57570 Resolves: RHEL-57578 - Fix REXML DoS when parsing an XML having many specific characters such as whitespace character, ] and ]. (CVE-2024-41123) Resolves: RHEL-57567 - Fix incorrect symlink for rubygem-irb's library. Resolves: RHEL-57597 [3.3.1-2] - Upgrade to Ruby 3.3.1. Resolves: RHEL-37697 - Fix buffer overread vulnerability in StringIO. (CVE-2024-27280) Resolves: RHEL-37699 - Fix RCE vulnerability with .rdoc_options in RDoc. (CVE-2024-27281) Resolves: RHEL-37696 - Fix Arbitrary memory address read vulnerability with Regex search. (CVE-2024-27282) Resolves: RHEL-37698 [3.3.0-1] - Upgrade to Ruby 3.3.0. Resolves: RHEL-17089 [3.1.2-142] - Bypass git submodule test failure on Git = 2.38.1. - Fix tests with Europe/Amsterdam pre-1970 time on tzdata version 2022b. - Fix for tzdata-2022g. - Fix OpenSSL.fips_mode and OpenSSL::PKey.read in OpenSSL 3 FIPS. Resolves: RHEL-5590 - ssl: use ffdhe2048 from RFC 7919 as the default DH group parameters Related: RHEL-5590 - Disable fiddle tests that use FFI closures. Related: RHEL-5590 rubygem-mysql2 [0.5.5-1] - Upgrade to mysql2 0.5.5. Related: RHEL-17089 rubygem-pg [1.5.4-1] - Upgrade to pg 1.5.4. Related: RHEL-17089
- Published
- unknown
- Last Modified
- unknown
CVSS details not available.
No product information available.
No references available.
No linked vulnerabilities found.
{
"cves": [
"CVE-2024-41123",
"CVE-2024-41946",
"CVE-2024-43398",
"CVE-2024-39908"
],
"cvss": 0.0,
"database_specific": {
"severity": "MODERATE"
},
"description": "ruby\n[3.3.5-3]\n- Upgrade to Ruby 3.3.5\n Resolves: RHEL-57576\n- Fix DoS vulnerability in rexml.\n (CVE-2024-39908)\n (CVE-2024-41946)\n (CVE-2024-43398)\n Resolves: RHEL-57573\n Resolves: RHEL-57570\n Resolves: RHEL-57578\n- Fix REXML DoS when parsing an XML having many specific characters such as\n whitespace character, ] and ].\n (CVE-2024-41123)\n Resolves: RHEL-57567\n- Fix incorrect symlink for rubygem-irb's library.\n Resolves: RHEL-57597\n\n[3.3.1-2]\n- Upgrade to Ruby 3.3.1.\n Resolves: RHEL-37697\n- Fix buffer overread vulnerability in StringIO.\n (CVE-2024-27280)\n Resolves: RHEL-37699\n- Fix RCE vulnerability with .rdoc_options in RDoc.\n (CVE-2024-27281)\n Resolves: RHEL-37696\n- Fix Arbitrary memory address read vulnerability with Regex search.\n (CVE-2024-27282)\n Resolves: RHEL-37698\n\n[3.3.0-1]\n- Upgrade to Ruby 3.3.0.\n Resolves: RHEL-17089\n\n[3.1.2-142]\n- Bypass git submodule test failure on Git = 2.38.1.\n- Fix tests with Europe/Amsterdam pre-1970 time on tzdata version 2022b.\n- Fix for tzdata-2022g.\n- Fix OpenSSL.fips_mode and OpenSSL::PKey.read in OpenSSL 3 FIPS.\n Resolves: RHEL-5590\n- ssl: use ffdhe2048 from RFC 7919 as the default DH group parameters\n Related: RHEL-5590\n- Disable fiddle tests that use FFI closures.\n Related: RHEL-5590\n\nrubygem-mysql2\n[0.5.5-1]\n- Upgrade to mysql2 0.5.5.\n Related: RHEL-17089\n\nrubygem-pg\n[1.5.4-1]\n- Upgrade to pg 1.5.4.\n Related: RHEL-17089",
"id": "ELSA-2024-6785",
"ovalId": "oval:com.oracle.elsa:def:20246785",
"source": "oracle_linux",
"title": "ELSA-2024-6785: ruby:3.3 security update (MODERATE)",
"url": "https://linux.oracle.com/errata/ELSA-2024-6785.html"
}