USN-5806-2: Ruby vulnerability
USN-5806-1 fixed vulnerabilities in Ruby. This update fixes the problem for Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.10. Original advisory details: Hiroshi Tokumaru discovered that Ruby did not properly handle certain user input for applications which generate HTTP responses using cgi gem. An attacker could possibly use this issue to maliciously modify the response a user would receive from a vulnerable application.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Ruby vulnerability?
The vulnerability ID for this Ruby vulnerability is USN-5806-2.
What is the affected software?
The affected software is Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.10 with Ruby versions 2.5.1-1ubuntu1.13, 3.0.2-7ubuntu2.3, and 3.0.4-7ubuntu0.1.
What is the severity of the USN-5806-2 vulnerability?
The severity of the USN-5806-2 vulnerability is not specified in the information provided.
How do I fix the USN-5806-2 vulnerability?
To fix the USN-5806-2 vulnerability, update Ruby to versions 2.5.1-1ubuntu1.13, 3.0.2-7ubuntu2.3, or 3.0.4-7ubuntu0.1 depending on your Ubuntu version.
Where can I find more information about the USN-5806-2 vulnerability?
You can find more information about the USN-5806-2 vulnerability in the following references: 1. [CVE-2021-33621](https://ubuntu.com/security/CVE-2021-33621) 2. [USN-5806-1](https://ubuntu.com/security/notices/USN-5806-1) 3. [USN-5806-3](https://ubuntu.com/security/notices/USN-5806-3)