USN-4882-1
Dashboard / Vulnerabilities / USN-4882-1
USN-4882-1
Summary: ruby2.3, ruby2.5, ruby2.7 vulnerabilities
Details: It was discovered that the Ruby JSON gem incorrectly handled certain JSON files. If a user or automated system were tricked into parsing a specially crafted JSON file, a remote attacker could use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-10663) It was discovered that Ruby incorrectly handled certain socket memory operations. A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-10933) It was discovered that Ruby incorrectly handled certain transfer-encoding headers when using Webrick. A remote attacker could possibly use this issue to bypass a reverse proxy. (CVE-2020-25613)
References: https://ubuntu.com/security/notices/USN-4882-1, https://ubuntu.com/security/CVE-2020-10663, https://ubuntu.com/security/CVE-2020-10933, https://ubuntu.com/security/CVE-2020-25613
Affected packages
Package
Name: ruby2.3
Purl: pkg:deb/ubuntu/[email protected]~ubuntu16.04.15?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
