QID 198635

Date Published: 2022-01-19

QID 198635: Ubuntu Security Notification for Ruby Vulnerabilities (USN-5235-1)

Ruby incorrectly handled certain html files.
Ruby incorrectly handled certain regular expressions.
Ruby incorrectly handled certain cookie names.

An attacker could possibly use this issue to cause a crash.
An attacker could possibly use this issue to cause a regular expressiondenial of service.
An attacker could possibly use this issue to access or exposesensitive information.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5235-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198635

    Software Advisories
    Advisory ID Software Component Link
    USN-5235-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5235-1