DSA-4259-1 ruby2.3 -- security update

Related Vulnerabilities: CVE-2017-17405   CVE-2017-17742   CVE-2017-17790   CVE-2018-6914   CVE-2018-8777   CVE-2018-8778   CVE-2018-8779   CVE-2018-8780   CVE-2018-1000073   CVE-2018-1000074   CVE-2018-1000075   CVE-2018-1000076   CVE-2018-1000077   CVE-2018-1000078   CVE-2018-1000079  

Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in incorrect processing of HTTP/FTP, directory traversal, command injection, unintended socket creation or information disclosure. This update also fixes several issues in RubyGems which could allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop, write arbitrary files, or run malicious code. For the stable distribution (stretch), these problems have been fixed in version 2.3.3-1+deb9u3. We recommend that you upgrade your ruby2.3 packages. For the detailed security status of ruby2.3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby2.3

Debian Security Advisory

DSA-4259-1 ruby2.3 -- security update

Date Reported:
31 Jul 2018
Affected Packages:
ruby2.3
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2017-17405, CVE-2017-17742, CVE-2017-17790, CVE-2018-6914, CVE-2018-8777, CVE-2018-8778, CVE-2018-8779, CVE-2018-8780, CVE-2018-1000073, CVE-2018-1000074, CVE-2018-1000075, CVE-2018-1000076, CVE-2018-1000077, CVE-2018-1000078, CVE-2018-1000079.
More information:

Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in incorrect processing of HTTP/FTP, directory traversal, command injection, unintended socket creation or information disclosure.

This update also fixes several issues in RubyGems which could allow an attacker to use specially crafted gem files to mount cross-site scripting attacks, cause denial of service through an infinite loop, write arbitrary files, or run malicious code.

For the stable distribution (stretch), these problems have been fixed in version 2.3.3-1+deb9u3.

We recommend that you upgrade your ruby2.3 packages.

For the detailed security status of ruby2.3 please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby2.3