Mageia 2020-0186: ruby-json security update
Summary
Updated ruby-json packages fix security vulnerability:
In ruby-json before 2.3.0, there is an unsafe object creation vulnerability.
When parsing certain JSON documents, the json gem can be coerced into
creating arbitrary objects in the target system (CVE-2020-10663).
References
- https://bugs.mageia.org/show_bug.cgi?id=26408
- https://www.ruby-lang.org/en/news/2020/03/19/json-dos-cve-2020-10663/
- https://www.debian.org/lts/security/2020/dla-2190
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10663
Resolution
MGASA-2020-0186 - Updated ruby-json packages fix security vulnerability
SRPMS
- 7/core/ruby-json-2.1.0-3.1.mga7