USN-3808-1: Ruby vulnerabilities
5 November 2018
Several security issues were fixed in Ruby.
- ruby1.9.1 - Object-oriented scripting language
- ruby2.0 - Object-oriented scripting language
- ruby2.3 - Object-oriented scripting language
- ruby2.5 - Interpreter of object-oriented scripting language Ruby
It was discovered that Ruby incorrectly handled certain X.509
certificates. An attacker could possibly use this issue to
bypass the certificate check. (CVE-2018-16395)
It was discovered that Ruby incorrectly handled certain
inputs. An attacker could possibly use this issue to execute
arbitrary code. (CVE-2018-16396)
The problem can be corrected by updating your system to the following package versions:
In general, a standard system update will make all the necessary changes.