MGASA-2019-0123

Source
https://advisories.mageia.org/MGASA-2019-0123.html
Import Source
https://advisories.mageia.org/MGASA-2019-0123.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2019-0123
Related
Published
2019-04-05T18:12:59Z
Modified
2019-04-05T17:34:53Z
Summary
Updated ruby-ox packages fix security vulnerability
Details

In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj (CVE-2017-15928).

Also, the package was broken and has been fixed to function properly.

References
Credits

Affected packages

Mageia:6 / ruby-ox

Package

Name
ruby-ox
Purl
pkg:rpm/mageia/ruby-ox?arch=source&distro=mageia-6

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.8.2-1.mga6

Ecosystem specific

{
    "section": "core"
}