Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:1582-1

Опубликовано: 09 июн. 2020
Источник: suse-cvrf

Описание

Security update for rubygem-bundler

This update for rubygem-bundler fixes the following issue:

  • CVE-2019-3881: Fixed insecure permissions on a directory in /tmp/ that allowed malicious code execution (bsc#1143436).

Список пакетов

Container bci/ruby:latest
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Container suse/rmt-server:latest
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-Azure-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-Azure-LI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-Azure-VLI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-EC2-HVM
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-EC2-HVM-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-GCE-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-OCI-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-CAP-Deployment-BYOS-EC2-HVM
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-CAP-Deployment-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-Azure-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-Azure-LI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-Azure-VLI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-EC2-HVM
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-EC2-HVM-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-GCE-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP1-SAP-OCI-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-CAP-Deployment-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-SAP-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-SAP-Azure-LI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-SAP-Azure-VLI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-SAP-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-SAP-BYOS-EC2-HVM
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-SAP-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-SAP-EC2-HVM
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP2-SAP-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP3-SAP-Azure-LI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP3-SAP-Azure-VLI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP3-SAP-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP3-SAP-BYOS-EC2-HVM
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP3-SAP-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Azure-LI-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Azure-LI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Azure-VLI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-BYOS-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Hardened
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Hardened-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Hardened-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Hardened-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Hardened-BYOS-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Hardened-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Hardened-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP4-SAP-Hardened-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Azure-3P
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Azure-LI-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Azure-LI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Azure-VLI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-BYOS-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Hardened-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Hardened-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Hardened-BYOS-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Hardened-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Hardened-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP5-SAP-Hardened-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Azure-LI-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Azure-LI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Azure-VLI-BYOS-Production
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-BYOS-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Hardened
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Hardened-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Hardened-BYOS
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-Azure
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Hardened-BYOS-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Hardened-EC2
ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SP6-SAP-Hardened-GCE
ruby2.5-rubygem-bundler-1.16.1-3.3.1
SUSE Linux Enterprise Module for Basesystem 15 SP1
ruby2.5-rubygem-bundler-1.16.1-3.3.1

Описание

Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.


Затронутые продукты
Container bci/ruby:latest:ruby2.5-rubygem-bundler-1.16.1-3.3.1
Container suse/rmt-server:latest:ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-Azure-BYOS:ruby2.5-rubygem-bundler-1.16.1-3.3.1
Image SLES15-SAP-Azure-LI-BYOS-Production:ruby2.5-rubygem-bundler-1.16.1-3.3.1

Ссылки