Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2025:7539

Опубликовано: 29 июл. 2025
Источник: rocky
Оценка: Moderate

Описание

Moderate: ruby:2.5 security update

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.

Security Fix(es):

  • oniguruma: integer overflow in search_in_range function in regexec.c leads to out-of-bounds read (CVE-2019-19012)

  • rubygem-bundler: unexpected code execution in Gemfiles (CVE-2021-43809)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
rubyaarch64114.module+el8.10.0+1979+815637dfruby-2.5.9-114.module+el8.10.0+1979+815637df.aarch64.rpm
ruby-develaarch64114.module+el8.10.0+1979+815637dfruby-devel-2.5.9-114.module+el8.10.0+1979+815637df.aarch64.rpm
ruby-docnoarch114.module+el8.10.0+1979+815637dfruby-doc-2.5.9-114.module+el8.10.0+1979+815637df.noarch.rpm
rubygem-abrtnoarch4.module+el8.5.0+738+032c9c02rubygem-abrt-0.3.0-4.module+el8.5.0+738+032c9c02.noarch.rpm
rubygem-abrtnoarch4.module+el8.9.0+1536+5f79634erubygem-abrt-0.3.0-4.module+el8.9.0+1536+5f79634e.noarch.rpm
rubygem-abrt-docnoarch4.module+el8.5.0+738+032c9c02rubygem-abrt-doc-0.3.0-4.module+el8.5.0+738+032c9c02.noarch.rpm
rubygem-abrt-docnoarch4.module+el8.9.0+1536+5f79634erubygem-abrt-doc-0.3.0-4.module+el8.9.0+1536+5f79634e.noarch.rpm
rubygem-bigdecimalaarch64114.module+el8.10.0+1979+815637dfrubygem-bigdecimal-1.3.4-114.module+el8.10.0+1979+815637df.aarch64.rpm
rubygem-bsonaarch642.module+el8.9.0+1536+5f79634erubygem-bson-4.3.0-2.module+el8.9.0+1536+5f79634e.aarch64.rpm
rubygem-bson-docnoarch2.module+el8.9.0+1536+5f79634erubygem-bson-doc-4.3.0-2.module+el8.9.0+1536+5f79634e.noarch.rpm

Показывать по

Связанные CVE

Связанные уязвимости

oracle-oval
около 1 года назад

ELSA-2025-7539: ruby:2.5 security update (MODERATE)

CVSS3: 9.8
ubuntu
больше 6 лет назад

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

CVSS3: 7.5
redhat
больше 6 лет назад

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

CVSS3: 9.8
nvd
больше 6 лет назад

An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a denial-of-service or information disclosure, or possibly have unspecified other impact, via a crafted regular expression.

CVSS3: 9.8
debian
больше 6 лет назад

An integer overflow in the search_in_range function in regexec.c in On ...