Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Ubuntu Security Notice USN-6838-1[6]
- Authored by Ubuntu[7] | Site security.ubuntu.com[8]
-
Ubuntu Security Notice 6838-1 - It was discovered that Ruby RDoc incorrectly parsed certain YAML files. If a user or automated system were tricked into parsing a specially crafted .rdoc_options file, a remote attacker could possibly use this issue to execute arbitrary code. It was discovered that the Ruby regex compiler incorrectly handled certain memory operations. A remote attacker could possibly use this issue to obtain sensitive memory contents.
- systems | linux[9], ubuntu[10]
- advisories | CVE-2024-27281[11], CVE-2024-27282[12]
- SHA-256 |
120b5d48766d2e4145ff11d42e77720c22fbb0e8c31ac33a57af9a29ab60b5c4 - Download[13] | Favorite[14] | View[15]
Change Mirror[16] Download[17]
==========================================================================
Ubuntu Security Notice USN-6838-1
June 17, 2024
ruby2.7, ruby3.0, ruby3.1, ruby3.2 vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
- Ubuntu 23.10
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
Summary:
Several security issues were fixed in Ruby.
Software Description:
- ruby3.2: Object-oriented scripting language
- ruby3.1: Object-oriented scripting language
- ruby3.0: Object-oriented scripting language
- ruby2.7: Object-oriented scripting language
Details:
It was discovered that Ruby RDoc incorrectly parsed certain YAML files. If
a user or automated system were tricked into parsing a specially crafted
.rdoc_options file, a remote attacker could possibly use this issue to
execute arbitrary code. (CVE-2024-27281)
It was discovered that the Ruby regex compiler incorrectly handled certain
memory operations. A remote attacker could possibly use this issue to
obtain sensitive memory contents. (CVE-2024-27282)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
libruby3.2 3.2.3-1ubuntu0.24.04.1
ruby3.2 3.2.3-1ubuntu0.24.04.1
Ubuntu 23.10
libruby3.1 3.1.2-7ubuntu3.2
ruby3.1 3.1.2-7ubuntu3.2
Ubuntu 22.04 LTS
libruby3.0 3.0.2-7ubuntu2.6
ruby3.0 3.0.2-7ubuntu2.6
Ubuntu 20.04 LTS
libruby2.7 2.7.0-5ubuntu1.13
ruby2.7 2.7.0-5ubuntu1.13
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-6838-1
CVE-2024-27281, CVE-2024-27282
Package Information:
https://launchpad.net/ubuntu/+source/ruby3.2/3.2.3-1ubuntu0.24.04.1
https://launchpad.net/ubuntu/+source/ruby3.1/3.1.2-7ubuntu3.2
https://launchpad.net/ubuntu/+source/ruby3.0/3.0.2-7ubuntu2.6
https://launchpad.net/ubuntu/+source/ruby2.7/2.7.0-5ubuntu1.13
File Tags
- ActiveX[23] (933)
- Advisory[24] (85,624)
- Arbitrary[25] (16,756)
- BBS[26] (2,859)
- Bypass[27] (1,836)
- CGI[28] (1,032)
- Code Execution[29] (7,713)
- Conference[30] (691)
- Cracker[31] (844)
- CSRF[32] (3,375)
- DoS[33] (24,860)
- Encryption[34] (2,388)
- Exploit[35] (52,970)
- File Inclusion[36] (4,255)
- File Upload[37] (987)
- Firewall[38] (822)
- Info Disclosure[39] (2,872)
- Intrusion Detection[40] (911)
- Java[41] (3,129)
- JavaScript[42] (894)
- Kernel[43] (7,103)
- Local[44] (14,741)
- Magazine[45] (586)
- Overflow[46] (13,126)
- Perl[47] (1,434)
- PHP[48] (5,215)
- Proof of Concept[49] (2,375)
- Protocol[50] (3,716)
- Python[51] (1,623)
- Remote[52] (31,536)
- Root[53] (3,621)
- Rootkit[54] (524)
- Ruby[55] (628)
- Scanner[56] (1,654)
- Security Tool[57] (8,009)
- Shell[58] (3,267)
- Shellcode[59] (1,217)
- Sniffer[60] (901)
- Spoof[61] (2,267)
- SQL Injection[62] (16,564)
- TCP[63] (2,435)
- Trojan[64] (690)
- UDP[65] (900)
- Virus[66] (669)
- Vulnerability[67] (32,806)
- Web[68] (9,927)
- Whitepaper[69] (3,778)
- x86[70] (967)
- XSS[71] (18,219)
- Other[72]
File Archives
- June 2024[73]
- May 2024[74]
- April 2024[75]
- March 2024[76]
- February 2024[77]
- January 2024[78]
- December 2023[79]
- November 2023[80]
- October 2023[81]
- September 2023[82]
- August 2023[83]
- July 2023[84]
- Older[85]
Systems
- AIX[86] (429)
- Apple[87] (2,089)
- BSD[88] (376)
- CentOS[89] (58)
- Cisco[90] (1,927)
- Debian[91] (7,061)
- Fedora[92] (1,693)
- FreeBSD[93] (1,246)
- Gentoo[94] (4,500)
- HPUX[95] (880)
- iOS[96] (375)
- iPhone[97] (108)
- IRIX[98] (220)
- Juniper[99] (69)
- Linux[100] (50,018)
- Mac OS X[101] (691)
- Mandriva[102] (3,105)
- NetBSD[103] (256)
- OpenBSD[104] (488)
- RedHat[105] (16,064)
- Slackware[106] (941)
- Solaris[107] (1,611)
- SUSE[108] (1,444)
- Ubuntu[109] (9,580)
- UNIX[110] (9,417)
- UnixWare[111] (187)
- Windows[112] (6,662)
- Other[113]
- Services
- Security Services[124]
- Hosting By
- Rokasec[125]
Read more https://packetstormsecurity.com/files/179114/USN-6838-1.txt


