Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
145615 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.883057
Categoría:CentOS Local Security Checks
Título:CentOS Update for ruby CESA-2019:1235 centos7
Resumen:The remote host is missing an update for the 'ruby'; package(s) announced via the CESA-2019:1235 advisory.
Descripción:Summary:
The remote host is missing an update for the 'ruby'
package(s) announced via the CESA-2019:1235 advisory.

Vulnerability Insight:
Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to perform system management tasks.

Security Fix(es):

* rubygems: Installing a malicious gem may lead to arbitrary code execution
(CVE-2019-8324)

* rubygems: Escape sequence injection vulnerability in gem owner
(CVE-2019-8322)

* rubygems: Escape sequence injection vulnerability in API response
handling (CVE-2019-8323)

* rubygems: Escape sequence injection vulnerability in errors
(CVE-2019-8325)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.

Affected Software/OS:
'ruby' package(s) on CentOS 7.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2019-8322
https://hackerone.com/reports/315087
https://lists.debian.org/debian-lts-announce/2020/08/msg00027.html
SuSE Security Announcement: openSUSE-SU-2019:1771 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2019-07/msg00036.html
Common Vulnerability Exposure (CVE) ID: CVE-2019-8323
https://hackerone.com/reports/315081
Common Vulnerability Exposure (CVE) ID: CVE-2019-8324
https://hackerone.com/reports/328571
RedHat Security Advisories: RHSA-2019:1972
https://access.redhat.com/errata/RHSA-2019:1972
Common Vulnerability Exposure (CVE) ID: CVE-2019-8325
https://hackerone.com/reports/317353
CopyrightCopyright (C) 2019 Greenbone AG

Esta es sólo una de 145615 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.