Oracle Linux 8 : ruby (ELSA-2024-4499)
Discription

The remote Oracle Linux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ELSA-2024-4499 advisory. – Fix ReDoS vulnerability – upstream's incomplete fix for CVE-2023-28755. (CVE-2023-36617) Resolves: RHEL-5614 – Fix Buffer overread vulnerability in StringIO. (CVE-2024-27280) Resolves: RHEL-34125 – Fix RCE vulnerability with .rdoc_options in RDoc. (CVE-2024-27281) Resolves: RHEL-34117 – Fix Arbitrary memory address read vulnerability with Regex search. (CVE-2024-27282) Resolves: RHEL-33867 Tenable has extracted the preceding description block directly from the Oracle Linux security advisory. Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version…Read More

Back to Main

Subscribe for the latest news: