RHSA-2018:0584: Important: rh-ruby24-ruby security, bug fix, and enhancement update
Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.The following packages have been upgraded to a later upstream version: rh-ruby24-ruby (2.4.3). (BZ#1549651)Security Fix(es): ruby: Command injection vulnerability in Net::FTP (CVE-2017-17405) ruby: Command injection in lib/resolv.rb:lazyinitialize() allows arbitrary code execution (CVE-2017-17790) For more details about the security issue(s), including the impact, a CVSS score, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2018:0584?
The severity of RHSA-2018:0584 is classified as important due to the potential impact on affected systems.
How do I fix RHSA-2018:0584?
To fix RHSA-2018:0584, upgrade the affected Ruby packages to version 2.4.3-90.el7 or later.
Which software versions are affected by RHSA-2018:0584?
RHSA-2018:0584 affects various packages within the rh-ruby24-ruby suite on both el6 and el7 systems.
Is RHSA-2018:0584 specific to a certain architecture?
Yes, RHSA-2018:0584 affects both x86_64 and noarch architectures depending on the specific package.
What should I do if I cannot upgrade my system for RHSA-2018:0584?
If upgrading is not possible for RHSA-2018:0584, consider implementing additional security measures to mitigate the risk.