openSUSE-SU-2021:3838-1
Dashboard / Vulnerabilities / openSUSE-SU-2021:3838-1
openSUSE-SU-2021:3838-1
Summary: Security update for ruby2.5
Details: This update for ruby2.5 fixes the following issues: - CVE-2021-31799: Fixed Command injection vulnerability in RDoc (bsc#1190375). - CVE-2021-31810: Fixed trusting FTP PASV responses vulnerability in Net:FTP (bsc#1188161). - CVE-2021-32066: Fixed StartTLS stripping vulnerability in Net:IMAP (bsc#1188160).
References: https://lists.opensuse.org/archives/list/[email protected]/thread/3CHM25JITRX6N3UKVDBKNLWS6MYWFY3M/, https://bugzilla.suse.com/1188160, https://bugzilla.suse.com/1188161, https://bugzilla.suse.com/1190375, https://www.suse.com/security/cve/CVE-2021-31799, https://www.suse.com/security/cve/CVE-2021-31810, https://www.suse.com/security/cve/CVE-2021-32066
Affected packages
Package
Name: ruby2.5
Purl: pkg:rpm/opensuse/ruby2.5&distro=openSUSE%20Leap%2015.3
Affected ranges
Type: ECOSYSTEM
Events:
