Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2025-8131

Опубликовано: 27 июн. 2025
Источник: oracle-oval
Платформа: Oracle Linux 10

Описание

ELSA-2025-8131: ruby security update (MODERATE)

[3.3.8-10]

  • Upgrade to Ruby 3.3.8. Resolves: RHEL-87342
  • Fix Net::IMAP vulnerable to possible DoS by memory exhaustion. (CVE-2025-25186)
  • Fix Denial of Service in CGI::Cookie.parse. (CVE-2025-27219) Resolves: RHEL-86116
  • Fix userinfo leakage in URI#join, URI#merge and URI#+. (CVE-2025-27221)

Обновленные пакеты

Oracle Linux 10

Oracle Linux aarch64

ruby

3.3.8-10.el10_0

ruby-bundled-gems

3.3.8-10.el10_0

ruby-default-gems

3.3.8-10.el10_0

ruby-devel

3.3.8-10.el10_0

ruby-doc

3.3.8-10.el10_0

ruby-libs

3.3.8-10.el10_0

rubygem-bigdecimal

3.1.5-10.el10_0

rubygem-bundler

2.5.22-10.el10_0

rubygem-io-console

0.7.1-10.el10_0

rubygem-irb

1.13.1-10.el10_0

rubygem-json

2.7.2-10.el10_0

rubygem-minitest

5.20.0-10.el10_0

rubygem-power_assert

2.0.3-10.el10_0

rubygem-psych

5.1.2-10.el10_0

rubygem-racc

1.7.3-10.el10_0

rubygem-rake

13.1.0-10.el10_0

rubygem-rbs

3.4.0-10.el10_0

rubygem-rdoc

6.6.3.1-10.el10_0

rubygem-rexml

3.3.9-10.el10_0

rubygem-rss

0.3.1-10.el10_0

rubygem-test-unit

3.6.1-10.el10_0

rubygem-typeprof

0.21.9-10.el10_0

rubygems

3.5.22-10.el10_0

rubygems-devel

3.5.22-10.el10_0

Oracle Linux x86_64

ruby

3.3.8-10.el10_0

ruby-bundled-gems

3.3.8-10.el10_0

ruby-default-gems

3.3.8-10.el10_0

ruby-devel

3.3.8-10.el10_0

ruby-doc

3.3.8-10.el10_0

ruby-libs

3.3.8-10.el10_0

rubygem-bigdecimal

3.1.5-10.el10_0

rubygem-bundler

2.5.22-10.el10_0

rubygem-io-console

0.7.1-10.el10_0

rubygem-irb

1.13.1-10.el10_0

rubygem-json

2.7.2-10.el10_0

rubygem-minitest

5.20.0-10.el10_0

rubygem-power_assert

2.0.3-10.el10_0

rubygem-psych

5.1.2-10.el10_0

rubygem-racc

1.7.3-10.el10_0

rubygem-rake

13.1.0-10.el10_0

rubygem-rbs

3.4.0-10.el10_0

rubygem-rdoc

6.6.3.1-10.el10_0

rubygem-rexml

3.3.9-10.el10_0

rubygem-rss

0.3.1-10.el10_0

rubygem-test-unit

3.6.1-10.el10_0

rubygem-typeprof

0.21.9-10.el10_0

rubygems

3.5.22-10.el10_0

rubygems-devel

3.5.22-10.el10_0

Связанные уязвимости

oracle-oval
3 месяца назад

ELSA-2025-4493: ruby:3.3 security update (MODERATE)

oracle-oval
около 1 месяца назад

ELSA-2025-10217: ruby:3.3 security update (MODERATE)

oracle-oval
3 месяца назад

ELSA-2025-4488: ruby:3.1 security update (MODERATE)

oracle-oval
4 месяца назад

ELSA-2025-4063: ruby:3.1 security update (MODERATE)

CVSS3: 3.2
ubuntu
5 месяцев назад

In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.