Melite Ruby 2.6.5, 2.5.7 na 2.4.8 nwere adịghị ike edoziri.

Ewepụtala mmezi asụsụ mmemme Ruby 2.6.5, 2.5.7 и 2.4.8, nke doziri adịghị ike anọ. Ihe ọghọm kachasị dị ize ndụ (CVE-2019-16255) n'ọbá akwụkwọ ọkọlọtọ Shell (lib/shell.rb), nke ọ na-enye ohere mee mgbanwe koodu. Ọ bụrụ na a na-ahazi data enwetara n'aka onye ọrụ na arụmụka mbụ nke Shell#[] ma ọ bụ Shell # ụzọ ule eji elele ọnụnọ nke faịlụ, onye na-awakpo nwere ike ime ka a kpọọ usoro Ruby aka ike.

Nsogbu ndị ọzọ:

  • CVE-2019-16254 - ikpughe na ihe nkesa http arụnyere n'ime ya WEBrick Mwakpo nkewa nzaghachi HTTP (ọ bụrụ na mmemme na-etinye data akwadoghị n'ime isi okwu nzaghachi HTTP, mgbe ahụ enwere ike kewaa isi okwu site na ịtinye agwa ahịrị ọhụrụ);
  • CVE-2019-15845 ngbanwe nke njirimara efu (\0) n'ime ndị a na-enyocha site na usoro "File.fnmatch" na "File.fnmatch?" Enwere ike iji ụzọ faịlụ kpalite ego n'ụzọ ụgha;
  • CVE-2019-16201 - agọnarị ọrụ na modul nyocha Diges maka WEBrick.

isi: opennet.ru

Tinye a comment