RHSA-2020:2288: Moderate: ruby security update
Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.Security Fix(es): ruby: HTTP response splitting in WEBrick (CVE-2017-17742) ruby: Buffer under-read in String#unpack (CVE-2018-8778) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Affected Software
Remediation
Event History
Frequently Asked Questions
What vulnerabilities does RHSA-2020:2288 address?
RHSA-2020:2288 addresses HTTP response splitting in WEBrick (CVE-2017-17742) and a buffer under-read in the Ruby language.
What is the severity level of RHSA-2020:2288?
The severity level of RHSA-2020:2288 is classified as moderate.
How do I fix RHSA-2020:2288?
To fix RHSA-2020:2288, update the affected Ruby packages to version 2.0.0.648-37.el7_6 or later.
Which Ruby packages are affected by RHSA-2020:2288?
The affected packages include ruby, ruby-devel, ruby-libs, ruby-debuginfo, and several associated Ruby gem packages.
Is it safe to continue using an affected version of Ruby after RHSA-2020:2288?
It is not recommended to continue using affected versions of Ruby, as unresolved vulnerabilities can be exploited.