RHSA-2019:1148HighCVSS 7.4
Red Hat Security Advisory: rh-ruby25-ruby security, bug fix, and enhancement update
🔗 CVE IDs covered (6)
📋 Description
CVE-2019-8320 — rubygems: Delete directory using symlink when decompressing tar CVE-2019-8321 — rubygems: Escape sequence injection vulnerability in verbose CVE-2019-8322 — rubygems: Escape sequence injection vulnerability in gem owner CVE-2019-8323 — rubygems: Escape sequence injection vulnerability in API response handling CVE-2019-8324 — rubygems: Installing a malicious gem may lead to arbitrary code execution CVE-2019-8325 — rubygems: Escape sequence injection vulnerability in errors
🔗 References (10)
- selfhttps://access.redhat.com/errata/RHSA-2019:1148
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1692512
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1692514
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1692516
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1692519
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1692520
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1692522
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1700274
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2019/rhsa-2019_1148.json