SUSE: 2020:1570-1 important: ruby2.1
Summary
This update for ruby2.1 fixes the following issues: Security issues fixed: - CVE-2015-9096: Fixed an SMTP command injection via CRLFsequences in a RCPT TO or MAIL FROM command (bsc#1043983). - CVE-2016-7798: Fixed an IV Reuse in GCM Mode (bsc#1055265). - CVE-2017-0898: Fixed a buffer underrun vulnerability in Kernel.sprintf (bsc#1058755). - CVE-2017-0899: Fixed an issue with malicious gem specifications, insufficient sanitation when printing gem specifications could have included terminal characters (bsc#1056286). - CVE-2017-0900: Fixed an issue with malicious gem specifications, the query command could have led to a denial of service attack against clients (bsc#1056286). - CVE-2017-0901: Fixed an issue with malicious gem specifications, potentially overwriting arbitrary files on the client system (bsc#1056286). - CVE-2017-0902: Fixed an issue with malicious gem specifications, that could have enabled MITM a...
Read the Full AdvisoryReferences
#1043983 #1048072 #1055265 #1056286 #1056782
#1058754 #1058755 #1058757 #1062452 #1069607
#1069632 #1073002 #1078782 #1082007 #1082008
#1082009 #1082010 #1082011 #1082014 #1082058
#1087433 #1087434 #1087436 #1087437 #1087440
#1087441 #1112530 #1112532 #1130611 #1130617
#1130620 #1130622 #1130623 #1130627 #1152990
#1152992 #1152994 #1152995 #1171517 #1172275
Cross- CVE-2015-9096 CVE-2016-2339 CVE-2016-7798
CVE-2017-0898 CVE-2017-0899 CVE-2017-0900
CVE-2017-0901 CVE-2017-0902 CVE-2017-0903
CVE-2017-10784 CVE-2017-14033 CVE-2017-14064
CVE-2017-17405 CVE-2017-17742 CVE-2017-17790
CVE-2017-9228 CVE-2017-9229 CVE-2018-1000073
CVE-2018-1000074 CVE-2018-1000075 CVE-2018-1000076
CVE-2018-10000...
Read the Full Advisory