Search CVE reports


Toggle filters

1 – 2 of 2 results


CVE-2026-54371

Medium priority

Some fixes available 7 of 8

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory...

1 affected package

attr

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
attr Fixed Fixed Fixed Fixed Fixed
Show less packages

CVE-2016-7798

Low priority

Some fixes available 5 of 16

The openssl gem for Ruby uses the same initialization vector (IV) in GCM Mode (aes-*-gcm) when the IV is set before the key, which makes it easier for context-dependent attackers to bypass the encryption protection mechanism.

7 affected packages

ruby-attr-encrypted, ruby-encryptor, ruby1.8, ruby1.9.1, ruby2.0...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
ruby-attr-encrypted Not affected Not affected Not affected Not affected Not in release
ruby-encryptor Not affected Not affected Not affected Not affected Not in release
ruby1.8 Not in release Not in release Not in release Not in release Not in release
ruby1.9.1 Not in release Not in release Not in release Not in release Not in release
ruby2.0 Not in release Not in release Not in release Not in release Not in release
ruby2.1 Not in release Not in release Not in release Not in release Not in release
ruby2.3 Not in release Not in release Not in release Not in release Not in release
Show all 7 packages Show less packages