it-securitynotifies AT lists.piratenpartei.de
Betreff: Sicherheitsankündigungen
Listenarchiv
- From: Salvatore Bonaccorso <carnil AT debian.org>
- To: debian-security-announce AT lists.debian.org
- Subject: [IT-SecNots] [SECURITY] [DSA 4721-1] ruby2.5 security update
- Date: Wed, 08 Jul 2020 15:31:57 +0000
- List-archive: https://lists.debian.org/msgid-search/E1jtC3B-0004DI-3J AT seger.debian.org
- List-id: <debian-security-announce.lists.debian.org>
- List-url: <http://lists.debian.org/debian-security-announce/>
- Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Date:Message-Id:Subject:To:From:Reply-To:Cc:MIME-Version :Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=L14+jJLunO/k41pmlZsw3Meywl9VOg6X8Em3ZPf0TbU=; b=k2 LnG05KP/DWAF54MnPshbxi6jIpiYxVjDjfu3mup0eLIW3E13g4+1/DCvHzW6eOMpAeE/PNAXlig82 cOJ0l4BLKeTJMY0MxFacuhk7Js/iy/zmEJFNmfYLHDCS/kFXmbHScyXX1lOYsFHQ+7fmJiOhlIlhc n7/H3n7eN3YkzW7pl4HxNOqbezKj64i4vTRR/GaZBEMxFegeljS+HKoDGy3UjvrwBbMt2LB54EwBW cfpmNmr2ApoEFTQdPQLFBgYJffgRyyy4Kb7MLEnUPprUL7F2YtA0p1y43hltXoBdZA0HpUgDfaqSL u2MVDSwc7zaxhG0AzWBbNIyvWOayK15w==;
- Old-return-path: <carnil AT seger.debian.org>
- Priority: urgent
- Resent-date: Wed, 8 Jul 2020 15:32:14 +0000 (UTC)
- Resent-from: debian-security-announce AT lists.debian.org
- Resent-message-id: <nkMpMFpD3bI.A.HcE.9beBfB@bendel>
- Resent-sender: debian-security-announce-request AT lists.debian.org
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian Security Advisory DSA-4721-1 security AT debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
July 08, 2020 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : ruby2.5
CVE ID : CVE-2020-10663 CVE-2020-10933
Several vulnerabilities have been discovered in the interpreter for the
Ruby language.
CVE-2020-10663
Jeremy Evans reported an unsafe object creation vulnerability in the
json gem bundled with Ruby. When parsing certain JSON documents, the
json gem can be coerced into creating arbitrary objects in the
target system.
CVE-2020-10933
Samuel Williams reported a flaw in the socket library which may lead
to exposure of possibly sensitive data from the interpreter.
For the stable distribution (buster), these problems have been fixed in
version 2.5.5-3+deb10u2.
We recommend that you upgrade your ruby2.5 packages.
For the detailed security status of ruby2.5 please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/ruby2.5
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----
iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAl8F5jVfFIAAAAAALgAo
aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2
NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND
z0RT1Q/9EmtF3l9EwsTqV0RaU0CvycnypEEHk0vahqwtDKe5m1j13RlbhU5PfeNm
n8E4pzw30+zROL8vxrCBQbAkBLACJOD9GwnA1G5mUnga1m49+5TyHEfPTFDsZHZ7
XqWuIJiQpOaPAi9xlywyqxji8OHPND2NNtCF1xk3Mpfk/7Y5JNJjFPnQnprfB4Hf
c8AMjgmjV4ElJ60ALpXQzP7snVs4S+LA+Qb2O7V05u8zW0ytiEGTJNKrdG/+Rkrm
XKUrEwPJLOU9DlR1JDXD491tOSYGiQdS/vWNQsyGKArpdDbhAUOybWZinD6ZG0KR
L7atC327+eNDhpIKcmS4jMRnoQwjmlgPK6m0YwF4mKmyL4lWKwqCddDnIfr7jRSq
bW3esnLJatEJiUbcSLpuBn0qO5f6HYb1iRhXJDQlPsuySIjObkn+rim9Bvo0NOQZ
SZx74Rv1KX/kYpU4KcZyoygRuuWzl3pPYRj5BYJOViDGIcSKay4w7oypLjSWg7b3
BQfKQ7MbIVIXLk27fS/mOKpG0uXM5cer7LGnZSovl+KQmgp4gBdtCpuzat7Jz3YI
tJDwDSjfhUQu8Uew+6bnvDUJ+zFEp/fEly2ueZFSYkkPmWPMcaI3OIk/Q2dLt5ZX
gC+Vad6gT/C2UBYZCxxcBTHOcAlImTQ/JPCQMOGrvZM6t7QouuA=
=rTdk
-----END PGP SIGNATURE-----
- [IT-SecNots] [SECURITY] [DSA 4721-1] ruby2.5 security update, Salvatore Bonaccorso, 08.07.2020
Archiv bereitgestellt durch MHonArc 2.6.19.