Ubuntu Security Notice USN-3365-1
25th July, 2017
ruby1.9.1, ruby2.0, ruby2.3 vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 17.04
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary
Several security issues were fixed in Ruby.
Software description
- ruby1.9.1
- Object-oriented scripting language
- ruby2.0
- Object-oriented scripting language
- ruby2.3
- Object-oriented scripting language
Details
It was discovered that Ruby DL::dlopen incorrectly handled opening
libraries. An attacker could possibly use this issue to open libraries with
tainted names. This issue only applied to Ubuntu 14.04 LTS. ()
Christian Hofstaedtler discovered that Ruby Fiddle::Handle incorrectly
handled certain crafted strings. An attacker could use this issue to cause
a denial of service, or possibly execute arbitrary code. This issue only
applied to Ubuntu 14.04 LTS. ()
Marcin Noga discovered that Ruby incorrectly handled certain arguments in
a TclTkIp class method. An attacker could possibly use this issue to
execute arbitrary code. This issue only affected Ubuntu 14.04 LTS.
()
It was discovered that Ruby incorrectly handled the initialization vector
(IV) in GCM mode. An attacker could possibly use this issue to bypass
encryption. (
.
In general, a standard system update will make all the necessary changes.
References
,
,
,
CVE-2016-7798
SOCIAL SHARE CARD GENERATOR