Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-4487

Опубликовано: 07 мая 2025
Источник: oracle-oval
Платформа: Oracle Linux 9

Описание

ELSA-2025-4487: ruby security update (MODERATE)

[3.0.7-165]

  • Fix Denial of Service in CGI::Cookie.parse. (CVE-2025-27219) Resolves: RHEL-86104
  • Fix ReDoS in CGI::Util#escapeElement. (CVE-2025-27220) Resolves: RHEL-86130

[3.0.7-164]

  • Undefine GC compaction methods on ppc64le. Resolves: RHEL-83136
  • Fix printing warnings when using IRB from a script. Resolves: RHEL-83044

Обновленные пакеты

Oracle Linux 9

Oracle Linux aarch64

ruby-doc

3.0.7-165.el9_5

ruby

3.0.7-165.el9_5

ruby-default-gems

3.0.7-165.el9_5

ruby-devel

3.0.7-165.el9_5

ruby-libs

3.0.7-165.el9_5

rubygem-bigdecimal

3.0.0-165.el9_5

rubygem-bundler

2.2.33-165.el9_5

rubygem-io-console

0.5.7-165.el9_5

rubygem-irb

1.3.5-165.el9_5

rubygem-json

2.5.1-165.el9_5

rubygem-minitest

5.14.2-165.el9_5

rubygem-power_assert

1.2.1-165.el9_5

rubygem-psych

3.3.2-165.el9_5

rubygem-rake

13.0.3-165.el9_5

rubygem-rbs

1.4.0-165.el9_5

rubygem-rdoc

6.3.4.1-165.el9_5

rubygem-rexml

3.2.5-165.el9_5

rubygem-rss

0.2.9-165.el9_5

rubygem-test-unit

3.3.7-165.el9_5

rubygem-typeprof

0.15.2-165.el9_5

rubygems

3.2.33-165.el9_5

rubygems-devel

3.2.33-165.el9_5

Oracle Linux x86_64

ruby

3.0.7-165.el9_5

ruby-default-gems

3.0.7-165.el9_5

ruby-devel

3.0.7-165.el9_5

ruby-libs

3.0.7-165.el9_5

rubygem-bigdecimal

3.0.0-165.el9_5

rubygem-bundler

2.2.33-165.el9_5

rubygem-io-console

0.5.7-165.el9_5

rubygem-irb

1.3.5-165.el9_5

rubygem-json

2.5.1-165.el9_5

rubygem-minitest

5.14.2-165.el9_5

rubygem-power_assert

1.2.1-165.el9_5

rubygem-psych

3.3.2-165.el9_5

rubygem-rake

13.0.3-165.el9_5

rubygem-rbs

1.4.0-165.el9_5

rubygem-rdoc

6.3.4.1-165.el9_5

rubygem-rexml

3.2.5-165.el9_5

rubygem-rss

0.2.9-165.el9_5

rubygem-test-unit

3.3.7-165.el9_5

rubygem-typeprof

0.15.2-165.el9_5

rubygems

3.2.33-165.el9_5

rubygems-devel

3.2.33-165.el9_5

ruby-doc

3.0.7-165.el9_5

Связанные CVE

Связанные уязвимости

CVSS3: 7.5
redos
2 месяца назад

Множественные уязвимости ruby

suse-cvrf
около 2 месяцев назад

Security update for ruby2.5

oracle-oval
около 2 месяцев назад

ELSA-2025-4488: ruby:3.1 security update (MODERATE)

oracle-oval
около 2 месяцев назад

ELSA-2025-4063: ruby:3.1 security update (MODERATE)

CVSS3: 4
ubuntu
4 месяца назад

In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.