USN-3365-1: Ruby vulnerabilities
It was discovered that Ruby DL::dlopen incorrectly handled opening libraries. An attacker could possibly use this issue to open libraries with tainted names. This issue only applied to Ubuntu 14.04 LTS. (CVE-2009-5147) Tony Arcieri, Jeffrey Walton, and Steffan Ullrich discovered that the Ruby OpenSSL extension incorrectly handled hostname wildcard matching. This issue only applied to Ubuntu 14.04 LTS. (CVE-2015-1855) Christian Hofstaedtler discovered that Ruby Fiddle::Handle incorrectly handled certain crafted strings. An attacker could use this issue to cause a denial of service, or possibly execute arbitrary code. This issue only applied to Ubuntu 14.04 LTS. (CVE-2015-7551) It was discovered that Ruby Net::SMTP incorrectly handled CRLF sequences. A remote attacker could possibly use this issue to inject SMTP commands. (CVE-2015-9096) Marcin Noga discovered that Ruby incorrectly handled certain arguments in a TclTkIp class method. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2016-2337) It was discovered that Ruby Fiddle::Function.new incorrectly handled certain arguments. An attacker could possibly use this issue to execute arbitrary code. This issue only affected Ubuntu 14.04 LTS. (CVE-2016-2339) It was discovered that Ruby incorrectly handled the initialization vector (IV) in GCM mode. An attacker could possibly use this issue to bypass encryption. (CVE-2016-7798)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-3365-1?
The severity of USN-3365-1 is categorized as a medium risk vulnerability.
How do I fix USN-3365-1?
To fix USN-3365-1, upgrade to the recommended package versions specifically for your Ubuntu release, such as libruby2.0 version 2.0.0.484-1ubuntu2.4 for Ubuntu 14.04.
Which Ubuntu versions are affected by USN-3365-1?
USN-3365-1 affects Ubuntu 14.04, 16.04, and 17.04, with specific packages being targeted in each version.
What is CVE-2009-5147 associated with USN-3365-1?
CVE-2009-5147 is a vulnerability related to Ruby's handling of library opening that can lead to potential security risks.
Who discovered the vulnerability reported in USN-3365-1?
The vulnerability in USN-3365-1 was discovered by researchers Tony Arcieri, Jeffrey Walton, and Steffan Ullrich.