QID 198302
Date Published: 2021-03-31
QID 198302: Ubuntu Security Notification for Ruby2.3, Ruby2.5, Ruby2.7 Vulnerabilities (USN-4882-1)
It was discovered that the Ruby JSON gem incorrectly handled certain JSON files.
It was discovered that Ruby incorrectly handled certain socket memory operations.
It was discovered that Ruby incorrectly handled certain transfer-encoding headers when using Webrick.
If a user or automated system were tricked into parsing a specially crafted JSON file, a remote attacker could use this issue to execute arbitrary code. This issue only affected Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. (CVE-2020-10663)
A remote attacker could possibly use this issue to obtain sensitive information. This issue only affected Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. (CVE-2020-10933)
A remote attacker could possibly use this issue to bypass a reverse proxy. (CVE-2020-25613)
- USN-4882-1 -
usn.ubuntu.com/4882-1/
CVEs related to QID 198302
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4882-1 | 16.04 (Xenial) on src | libruby2.3 |
|
| USN-4882-1 | 16.04 (Xenial) on src | ruby2.3 |
|
| USN-4882-1 | 18.04 (bionic) on src | libruby2.5 |
|
| USN-4882-1 | 18.04 (bionic) on src | ruby2.5 |
|
| USN-4882-1 | 20.04 (focal) on src | libruby2.7 |
|
| USN-4882-1 | 20.04 (focal) on src | ruby2.7 |
|
| USN-4882-1 | 20.10 (groovy) on src | libruby2.7 |
|
| USN-4882-1 | 20.10 (groovy) on src | ruby2.7 |
|