SUSE-SU-2017:0914-1

Source
https://www.suse.com/support/update/announcement/2017/suse-su-20170914-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2017:0914-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2017:0914-1
Related
Published
2017-04-03T15:26:04Z
Modified
2017-04-03T15:26:04Z
Summary
Security update for ruby19
Details

This update for ruby19 fixes the following issues:

Security issue fixed: - CVE-2016-2339: heap overflow vulnerability in the Fiddle::Function.new'initialize' (bsc#1018808)

Bugfixes: - fix small mistake in the backport for (bsc#986630) - HTTP Header injection in 'net/http' (bsc#986630) - make the testsuite work with our new openssl requirements

References

Affected packages

SUSE:Studio Onsite 1.3 / ruby19

Package

Name
ruby19
Purl
pkg:rpm/suse/ruby19&distro=SUSE%20Studio%20Onsite%201.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.3.p392-0.26.1

Ecosystem specific

{
    "binaries": [
        {
            "ruby19-devel-extra": "1.9.3.p392-0.26.1",
            "ruby19": "1.9.3.p392-0.26.1",
            "ruby19-devel": "1.9.3.p392-0.26.1"
        }
    ]
}

SUSE:Studio Onsite Runner 1.3 / ruby19

Package

Name
ruby19
Purl
pkg:rpm/suse/ruby19&distro=SUSE%20Studio%20Onsite%20Runner%201.3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.9.3.p392-0.26.1

Ecosystem specific

{
    "binaries": [
        {
            "ruby19-devel-extra": "1.9.3.p392-0.26.1",
            "ruby19": "1.9.3.p392-0.26.1",
            "ruby19-devel": "1.9.3.p392-0.26.1"
        }
    ]
}