Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2018-16396

Опубликовано: 17 окт. 2018
Источник: redhat
CVSS3: 5.9

Описание

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

Отчет

Subscription Asset Manager is now in a reduced support phase receiving only Critical impact security fixes. This issue has been rated as having a security impact of Low, and is not currently planned to be addressed in future updates. Red Hat Virtualization includes a vulnerable version of ruby, however the affected functionality is not used in Red Hat Virtualization or any of its dependencies. A future update may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5rubyWill not fix
Red Hat Enterprise Linux 6rubyWill not fix
Red Hat Enterprise Linux 8rubyNot affected
Red Hat Subscription Asset Managerruby193Will not fix
Red Hat Virtualization 4rubyWill not fix
Red Hat Enterprise Linux 7rubyFixedRHSA-2019:202806.08.2019
Red Hat Enterprise Linux 7.4 Advanced Update SupportrubyFixedRHSA-2020:276930.06.2020
Red Hat Enterprise Linux 7.4 Telco Extended Update SupportrubyFixedRHSA-2020:276930.06.2020
Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsrubyFixedRHSA-2020:276930.06.2020
Red Hat Enterprise Linux 7.6 Extended Update SupportrubyFixedRHSA-2020:283907.07.2020

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=1643089ruby: Tainted flags are not propagated in Array#pack and String#unpack with some directives

5.9 Medium

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
около 7 лет назад

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

CVSS3: 8.1
nvd
около 7 лет назад

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

CVSS3: 8.1
debian
около 7 лет назад

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5. ...

CVSS3: 8.1
github
больше 3 лет назад

An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5.x before 2.5.2, and 2.6.x before 2.6.0-preview3. It does not taint strings that result from unpacking tainted strings with some formats.

oracle-oval
больше 6 лет назад

ELSA-2019-2028: ruby security update (MODERATE)

5.9 Medium

CVSS3