Updates for Ruby 2.6.5, 2.5.7, and 2.4.8 addressing vulnerabilities.

Corrective releases have been issued for the Ruby programming language 2.6.5, 2.5.7 and 2.4.8, addressing four vulnerabilities. The most critical vulnerability (CVE-2019-16255) in the standard library Shell (lib/shell.rb), which , rather than taking focus. allows code injection. When processing data obtained from user inputs in the first argument of Shell#[] or Shell#test methods, used to check for file existence, an attacker can trigger arbitrary Ruby methods.

Other issues include:

  • CVE-2019-16254 — susceptibility of the built-in http server WEBrick to HTTP response splitting attacks (if a program inserts unvalidated data into the HTTP response header, it can split the header by inserting a newline character);
  • CVE-2019-15845 injection of a null character (\0) in file paths checked via the File.fnmatch and File.fnmatch? methods, which could lead to false positives during validation;
  • CVE-2019-16201 — denial of service in the Digest authentication module for WEBrick.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster