摘要:
ruby security update
安全等级: Medium
公告ID: KylinSec-SA-2024-2364
发布日期: 2024年10月31日
关联CVE: CVE-2024-27280 CVE-2024-27281
Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl).
Security Fix(es):
A buffer overread flaw was found in rubygem StringIO. The ungetbyte and ungetc methods on a StringIO object can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value.(CVE-2024-27280)
A flaw was found in Rubygem RDoc. When parsing .rdoc_options used for configuration in RDoc as a YAML file there are no restrictions on the classes that can be restored. This issue may lead to object injection, resulting in remote code execution.(CVE-2024-27281)
cve名称 | 产品 | 组件 | 是否受影响 |
---|---|---|---|
CVE-2024-27280 | KY3.5.2 | ruby | Fixed |
CVE-2024-27281 | KY3.5.2 | ruby | Fixed |
软件名称 | 架构 | 版本号 |
---|---|---|
rubygem-test-unit | noarch | 3.3.7-132.ky3_5.kb1 |
rubygems-devel | noarch | 3.2.32-132.ky3_5.kb1 |
ruby-irb | noarch | 3.0.3-132.ky3_5.kb1 |
rubygem-rbs | noarch | 1.4.0-132.ky3_5.kb1 |
rubygem-rdoc | noarch | 6.3.3-132.ky3_5.kb1 |
rubygem-rexml | noarch | 3.2.5-132.ky3_5.kb1 |
rubygem-bundler | noarch | 2.2.33-1.kb1.ky3_5 |
rubygem-did_you_mean | noarch | 1.5.0-132.ky3_5.kb1 |
rubygem-minitest | noarch | 5.14.2-132.ky3_5.kb1 |
ruby-help | noarch | 3.0.3-132.ky3_5.kb1 |
rubygem-rake | noarch | 13.0.3-132.ky3_5.kb1 |
rubygem-rss | noarch | 0.2.9-132.ky3_5.kb1 |
rubygems | noarch | 3.2.32-132.ky3_5.kb1 |
rubygem-typeprof | noarch | 0.15.2-132.ky3_5.kb1 |
rubygem-openssl | x86_64 | 2.2.1-132.ky3_5.kb1 |
rubygem-bigdecimal | x86_64 | 3.0.0-132.ky3_5.kb1 |
rubygem-psych | x86_64 | 3.3.2-132.ky3_5.kb1 |
ruby-devel | x86_64 | 3.0.3-132.ky3_5.kb1 |
rubygem-json | x86_64 | 2.5.1-132.ky3_5.kb1 |
rubygem-io-console | x86_64 | 0.5.7-132.ky3_5.kb1 |
ruby | x86_64 | 3.0.3-132.ky3_5.kb1 |
ruby-devel | aarch64 | 3.0.3-132.ky3_5.kb1 |
rubygem-io-console | aarch64 | 0.5.7-132.ky3_5.kb1 |
rubygem-openssl | aarch64 | 2.2.1-132.ky3_5.kb1 |
ruby | aarch64 | 3.0.3-132.ky3_5.kb1 |
rubygem-json | aarch64 | 2.5.1-132.ky3_5.kb1 |
rubygem-psych | aarch64 | 3.3.2-132.ky3_5.kb1 |
rubygem-bigdecimal | aarch64 | 3.0.0-132.ky3_5.kb1 |
方法一:下载安装包进行升级安装
1、通过下载链接下载需要升级的升级包保存,如 xxx.rpm
2、通过rpm命令升级,如 rpm -Uvh xxx.rpm
方法二:通过软件源进行升级安装
1、保持能够连接上互联网
2、通过yum命令升级指定的包,如 yum install 包名