MGASA-2017-0371

Source
https://advisories.mageia.org/MGASA-2017-0371.html
Import Source
https://advisories.mageia.org/MGASA-2017-0371.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2017-0371
Related
Published
2017-10-18T20:19:34Z
Modified
2017-10-18T19:57:59Z
Summary
Updated ruby packages fix security vulnerabilities
Details

If a malicious format string which contains a precious specifier (*) is passed and a huge minus value is also passed to the specifier, buffer underrun may be caused. In such situation, the result may contains heap, or the Ruby interpreter may crash (CVE-2017-0898).

If a malicious string is passed to the decode method of OpenSSL::ASN1, buffer underrun may be caused and the Ruby interpreter may crash (CVE-2017-14033).

The generate method of JSON module optionally accepts an instance of JSON::Ext::Generator::State class. If a malicious instance is passed, the result may include contents of heap (CVE-2017-14064).

When using the Basic authentication of WEBrick, clients can pass an arbitrary string as the user name. WEBrick outputs the passed user name intact to its log, then an attacker can inject malicious escape sequences to the log and dangerous control characters may be executed on a victim’s terminal emulator (CVE-2017-10784).

References
Credits

Affected packages

Mageia:6 / ruby

Package

Name
ruby
Purl
pkg:rpm/mageia/ruby?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.8-1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:6 / ruby-json

Package

Name
ruby-json
Purl
pkg:rpm/mageia/ruby-json?distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.3-3.1.mga6

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / ruby

Package

Name
ruby
Purl
pkg:rpm/mageia/ruby?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.0.0.p648-1.5.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / ruby-json

Package

Name
ruby-json
Purl
pkg:rpm/mageia/ruby-json?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.8.1-3.1.mga5

Ecosystem specific

{
    "section": "core"
}