An update for ruby is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP2 and openEuler-20.03-LTS-SP3
Security Advisory
openeuler-security@openeuler.org
openEuler security committee
openEuler-SA-2022-1497
Final
1.0
1.0
2022-01-22
Initial
2022-01-22
2022-01-22
openEuler SA Tool V1.0
2022-01-22
ruby security update
An update for ruby is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP2 and openEuler-20.03-LTS-SP3.
Object-oriented scripting language interpreter.
Security Fix(es):
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.(CVE-2021-41819)
An update for ruby is now available for openEuler-20.03-LTS-SP1,openEuler-20.03-LTS-SP2 and openEuler-20.03-LTS-SP3.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
High
ruby
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1497
https://www.openeuler.org/en/security/cve/detail.html?id=CVE-2021-41819
https://nvd.nist.gov/vuln/detail/CVE-2021-41819
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
openEuler-20.03-LTS-SP3
rubygem-openssl-2.1.2-115.oe1.aarch64.rpm
rubygem-bigdecimal-1.3.4-115.oe1.aarch64.rpm
ruby-2.5.8-115.oe1.aarch64.rpm
rubygem-json-2.1.0-115.oe1.aarch64.rpm
rubygem-psych-3.0.2-115.oe1.aarch64.rpm
ruby-devel-2.5.8-115.oe1.aarch64.rpm
ruby-debugsource-2.5.8-115.oe1.aarch64.rpm
rubygem-io-console-0.4.6-115.oe1.aarch64.rpm
ruby-debuginfo-2.5.8-115.oe1.aarch64.rpm
rubygem-json-2.1.0-115.oe1.aarch64.rpm
rubygem-io-console-0.4.6-115.oe1.aarch64.rpm
rubygem-openssl-2.1.2-115.oe1.aarch64.rpm
rubygem-bigdecimal-1.3.4-115.oe1.aarch64.rpm
ruby-devel-2.5.8-115.oe1.aarch64.rpm
ruby-2.5.8-115.oe1.aarch64.rpm
ruby-debuginfo-2.5.8-115.oe1.aarch64.rpm
ruby-debugsource-2.5.8-115.oe1.aarch64.rpm
rubygem-psych-3.0.2-115.oe1.aarch64.rpm
rubygem-bigdecimal-1.3.4-115.oe1.aarch64.rpm
ruby-debuginfo-2.5.8-115.oe1.aarch64.rpm
rubygem-io-console-0.4.6-115.oe1.aarch64.rpm
ruby-devel-2.5.8-115.oe1.aarch64.rpm
rubygem-openssl-2.1.2-115.oe1.aarch64.rpm
ruby-2.5.8-115.oe1.aarch64.rpm
ruby-debugsource-2.5.8-115.oe1.aarch64.rpm
rubygem-json-2.1.0-115.oe1.aarch64.rpm
rubygem-psych-3.0.2-115.oe1.aarch64.rpm
rubygem-rake-12.3.0-115.oe1.noarch.rpm
rubygem-rdoc-6.0.1.1-115.oe1.noarch.rpm
ruby-irb-2.5.8-115.oe1.noarch.rpm
rubygem-minitest-5.10.3-115.oe1.noarch.rpm
rubygem-xmlrpc-0.3.0-115.oe1.noarch.rpm
rubygem-net-telnet-0.1.1-115.oe1.noarch.rpm
rubygem-power_assert-1.1.1-115.oe1.noarch.rpm
rubygem-test-unit-3.2.7-115.oe1.noarch.rpm
rubygems-2.7.6-115.oe1.noarch.rpm
ruby-help-2.5.8-115.oe1.noarch.rpm
rubygems-devel-2.7.6-115.oe1.noarch.rpm
rubygem-did_you_mean-1.2.0-115.oe1.noarch.rpm
rubygems-2.7.6-115.oe1.noarch.rpm
rubygems-devel-2.7.6-115.oe1.noarch.rpm
rubygem-rake-12.3.0-115.oe1.noarch.rpm
rubygem-minitest-5.10.3-115.oe1.noarch.rpm
rubygem-rdoc-6.0.1.1-115.oe1.noarch.rpm
ruby-irb-2.5.8-115.oe1.noarch.rpm
rubygem-net-telnet-0.1.1-115.oe1.noarch.rpm
ruby-help-2.5.8-115.oe1.noarch.rpm
rubygem-test-unit-3.2.7-115.oe1.noarch.rpm
rubygem-did_you_mean-1.2.0-115.oe1.noarch.rpm
rubygem-xmlrpc-0.3.0-115.oe1.noarch.rpm
rubygem-power_assert-1.1.1-115.oe1.noarch.rpm
rubygem-net-telnet-0.1.1-115.oe1.noarch.rpm
rubygem-xmlrpc-0.3.0-115.oe1.noarch.rpm
rubygem-did_you_mean-1.2.0-115.oe1.noarch.rpm
rubygem-minitest-5.10.3-115.oe1.noarch.rpm
rubygem-power_assert-1.1.1-115.oe1.noarch.rpm
rubygem-rake-12.3.0-115.oe1.noarch.rpm
ruby-help-2.5.8-115.oe1.noarch.rpm
ruby-irb-2.5.8-115.oe1.noarch.rpm
rubygem-test-unit-3.2.7-115.oe1.noarch.rpm
rubygems-devel-2.7.6-115.oe1.noarch.rpm
rubygem-rdoc-6.0.1.1-115.oe1.noarch.rpm
rubygems-2.7.6-115.oe1.noarch.rpm
ruby-2.5.8-115.oe1.src.rpm
ruby-2.5.8-115.oe1.src.rpm
ruby-2.5.8-115.oe1.src.rpm
rubygem-io-console-0.4.6-115.oe1.x86_64.rpm
rubygem-openssl-2.1.2-115.oe1.x86_64.rpm
ruby-devel-2.5.8-115.oe1.x86_64.rpm
ruby-2.5.8-115.oe1.x86_64.rpm
ruby-debuginfo-2.5.8-115.oe1.x86_64.rpm
rubygem-psych-3.0.2-115.oe1.x86_64.rpm
rubygem-json-2.1.0-115.oe1.x86_64.rpm
ruby-debugsource-2.5.8-115.oe1.x86_64.rpm
rubygem-bigdecimal-1.3.4-115.oe1.x86_64.rpm
rubygem-json-2.1.0-115.oe1.x86_64.rpm
rubygem-openssl-2.1.2-115.oe1.x86_64.rpm
rubygem-bigdecimal-1.3.4-115.oe1.x86_64.rpm
ruby-devel-2.5.8-115.oe1.x86_64.rpm
ruby-debuginfo-2.5.8-115.oe1.x86_64.rpm
rubygem-io-console-0.4.6-115.oe1.x86_64.rpm
rubygem-psych-3.0.2-115.oe1.x86_64.rpm
ruby-2.5.8-115.oe1.x86_64.rpm
ruby-debugsource-2.5.8-115.oe1.x86_64.rpm
rubygem-json-2.1.0-115.oe1.x86_64.rpm
rubygem-openssl-2.1.2-115.oe1.x86_64.rpm
ruby-2.5.8-115.oe1.x86_64.rpm
ruby-debuginfo-2.5.8-115.oe1.x86_64.rpm
ruby-devel-2.5.8-115.oe1.x86_64.rpm
rubygem-io-console-0.4.6-115.oe1.x86_64.rpm
ruby-debugsource-2.5.8-115.oe1.x86_64.rpm
rubygem-bigdecimal-1.3.4-115.oe1.x86_64.rpm
rubygem-psych-3.0.2-115.oe1.x86_64.rpm
CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes in cookie names. This also affects the CGI gem through 0.3.0 for Ruby.
2022-01-22
CVE-2021-41819
openEuler-20.03-LTS-SP1
openEuler-20.03-LTS-SP2
openEuler-20.03-LTS-SP3
High
7.5
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
ruby security update
2022-01-22
https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1497