USN-6838-1: Ruby vulnerabilities
It was discovered that Ruby RDoc incorrectly parsed certain YAML files. If a user or automated system were tricked into parsing a specially crafted .rdocoptions file, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2024-27281) It was discovered that the Ruby regex compiler incorrectly handled certain memory operations. A remote attacker could possibly use this issue to obtain sensitive memory contents. (CVE-2024-27282)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6838-1?
The severity of USN-6838-1 is considered high due to the potential for remote code execution through crafted YAML files.
How do I fix USN-6838-1?
To fix USN-6838-1, upgrade your Ruby packages to the specified remedied versions listed in the advisory.
What are the affected versions in USN-6838-1?
The affected Ruby versions include 2.7, 3.0, 3.1, and 3.2 across various Ubuntu releases.
Can USN-6838-1 be exploited remotely?
Yes, USN-6838-1 can potentially be exploited remotely if a user or system parses a specially crafted .rdoc_options file.
Which Ubuntu releases are vulnerable to USN-6838-1?
The vulnerable Ubuntu releases include 20.04, 22.04, 23.10, and 24.04 as specified for each affected Ruby version.