USN-5020-1
Dashboard / Vulnerabilities / USN-5020-1
USN-5020-1
Summary: ruby2.3, ruby2.5, ruby2.7 vulnerabilities
Details: It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to execute arbitrary code. (CVE-2021-31799) It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to conduct port scans and service banner extractions. This issue only affected Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, Ubuntu 20.10, and Ubuntu 21.04. (CVE-2021-31810) It was discovered that Ruby incorrectly handled certain inputs. An attacker could possibly use this issue to perform machine-in-the-middle attackers to bypass the TLS protection. (CVE-2021-32066)
References: https://ubuntu.com/security/notices/USN-5020-1, https://ubuntu.com/security/CVE-2021-31799, https://ubuntu.com/security/CVE-2021-31810, https://ubuntu.com/security/CVE-2021-32066
Affected packages
Package
Name: ruby2.3
Purl: pkg:deb/ubuntu/ruby2.3?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
