ALAS-2022-1638

Related Vulnerabilities: CVE-2022-28739  

A buffer overrun vulnerability was found in Ruby. The issue occurs in a conversion algorithm from a String to a Float that causes process termination due to a segmentation fault, but under limited circumstances. This flaw may cause an illegal memory read. (CVE-2022-28739)

ALAS-2022-1638


Amazon Linux AMI Security Advisory: ALAS-2022-1638
Advisory Release Date: 2022-10-03 19:29 Pacific
Advisory Updated Date: 2022-10-10 20:41 Pacific
Severity: Medium
References: CVE-2022-28739 

Issue Overview:

A buffer overrun vulnerability was found in Ruby. The issue occurs in a conversion algorithm from a String to a Float that causes process termination due to a segmentation fault, but under limited circumstances. This flaw may cause an illegal memory read. (CVE-2022-28739)


Affected Packages:

ruby20


Issue Correction:
Run yum update ruby20 to update your system.

New Packages:
i686:
    rubygem20-io-console-0.4.2-2.41.amzn1.i686
    ruby20-devel-2.0.0.648-2.41.amzn1.i686
    ruby20-2.0.0.648-2.41.amzn1.i686
    ruby20-debuginfo-2.0.0.648-2.41.amzn1.i686
    rubygem20-bigdecimal-1.2.0-2.41.amzn1.i686
    ruby20-libs-2.0.0.648-2.41.amzn1.i686
    rubygem20-psych-2.0.0-2.41.amzn1.i686

noarch:
    ruby20-doc-2.0.0.648-2.41.amzn1.noarch
    ruby20-irb-2.0.0.648-2.41.amzn1.noarch
    rubygems20-2.0.14.1-2.41.amzn1.noarch
    rubygems20-devel-2.0.14.1-2.41.amzn1.noarch

src:
    ruby20-2.0.0.648-2.41.amzn1.src

x86_64:
    ruby20-libs-2.0.0.648-2.41.amzn1.x86_64
    rubygem20-bigdecimal-1.2.0-2.41.amzn1.x86_64
    rubygem20-psych-2.0.0-2.41.amzn1.x86_64
    rubygem20-io-console-0.4.2-2.41.amzn1.x86_64
    ruby20-2.0.0.648-2.41.amzn1.x86_64
    ruby20-debuginfo-2.0.0.648-2.41.amzn1.x86_64
    ruby20-devel-2.0.0.648-2.41.amzn1.x86_64