Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2021:0607-1

Опубликовано: 24 апр. 2021
Источник: suse-cvrf

Описание

Security update for ruby2.5

This update for ruby2.5 fixes the following issues:

  • Update to 2.5.9
  • CVE-2021-28965: XML round-trip vulnerability in REXML (bsc#1184644)

This update was imported from the SUSE:SLE-15:Update update project.

Список пакетов

openSUSE Leap 15.2
libruby2_5-2_5-2.5.9-lp152.2.6.1
ruby2.5-2.5.9-lp152.2.6.1
ruby2.5-devel-2.5.9-lp152.2.6.1
ruby2.5-devel-extra-2.5.9-lp152.2.6.1
ruby2.5-doc-2.5.9-lp152.2.6.1
ruby2.5-doc-ri-2.5.9-lp152.2.6.1
ruby2.5-stdlib-2.5.9-lp152.2.6.1

Описание

The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.


Затронутые продукты
openSUSE Leap 15.2:libruby2_5-2_5-2.5.9-lp152.2.6.1
openSUSE Leap 15.2:ruby2.5-2.5.9-lp152.2.6.1
openSUSE Leap 15.2:ruby2.5-devel-2.5.9-lp152.2.6.1
openSUSE Leap 15.2:ruby2.5-devel-extra-2.5.9-lp152.2.6.1

Ссылки
Уязвимость openSUSE-SU-2021:0607-1