MGASA-2017-0371

Advisory lineage Upstream: 4 Downstream: 0
Published: 18 Oct 2017, 20:19
Last modified:16 Apr 2026, 06:25

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

18 Oct 2017, 20:19
Published
Vulnerability first disclosed
16 Apr 2026, 06:25
Last Modified
Vulnerability information updated

Description

Updated ruby packages fix security vulnerabilities If a malicious format string which contains a precious specifier (*) is passed and a huge minus value is also passed to the specifier, buffer underrun may be caused. In such situation, the result may contains heap, or the Ruby interpreter may crash (CVE-2017-0898). If a malicious string is passed to the decode method of OpenSSL::ASN1, buffer underrun may be caused and the Ruby interpreter may crash (CVE-2017-14033). The generate method of JSON module optionally accepts an instance of JSON::Ext::Generator::State class. If a malicious instance is passed, the result may include contents of heap (CVE-2017-14064). When using the Basic authentication of WEBrick, clients can pass an arbitrary string as the user name. WEBrick outputs the passed user name intact to its log, then an attacker can inject malicious escape sequences to the log and dangerous control characters may be executed on a victim’s terminal emulator (CVE-2017-10784).

Affected Systems

  • mageiaruby

    < 2.0.0.p648-1.5.mga5

  • mageiaruby-json

    < 1.8.1-3.1.mga5

  • mageiaruby

    < 2.2.8-1.mga6

  • mageiaruby-json

    < 1.8.3-3.1.mga6

References (9)