{"id":20921,"date":"2022-02-22T09:31:43","date_gmt":"2022-02-22T06:31:43","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166075\/RHSA-2022-0582-01.txt"},"modified":"2022-02-22T10:11:58","modified_gmt":"2022-02-22T06:41:58","slug":"red-hat-security-advisory-2022-0582-01","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/red-hat-security-advisory-2022-0582-01\/","title":{"rendered":"Red Hat Security Advisory 2022-0582-01"},"content":{"rendered":"<p dir=\"ltr\">&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211;<br \/>\nHash: SHA256<\/p>\n<p dir=\"ltr\">=====================================================================<br \/>\nRed Hat Security Advisory<\/p>\n<p dir=\"ltr\">Synopsis: Important: ruby:2.6 security update<br \/>\nAdvisory ID: RHSA-2022:0582-01<br \/>\nProduct: Red Hat Enterprise Linux<br \/>\nAdvisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0582<br \/>\nIssue date: 2022-02-21<br \/>\nCVE Names: CVE-2019-15845 CVE-2019-16201 CVE-2019-16254<br \/>\nCVE-2019-16255 CVE-2020-10663 CVE-2020-10933<br \/>\nCVE-2020-25613 CVE-2020-36327 CVE-2021-28965<br \/>\nCVE-2021-31799 CVE-2021-31810 CVE-2021-32066<br \/>\nCVE-2021-41817 CVE-2021-41819<br \/>\n=====================================================================<\/p>\n<p dir=\"ltr\">1. Summary:<\/p>\n<p dir=\"ltr\">An update for the ruby:2.6 module is now available for Red Hat Enterprise<br \/>\nLinux 8.2 Extended Update Support.<\/p>\n<p dir=\"ltr\">Red Hat Product Security has rated this update as having a security impact<br \/>\nof Important. A Common Vulnerability Scoring System (CVSS) base score,<br \/>\nwhich gives a detailed severity rating, is available for each vulnerability<br \/>\nfrom the CVE link(s) in the References section.<\/p>\n<p dir=\"ltr\">2. Relevant releases\/architectures:<\/p>\n<p dir=\"ltr\">Red Hat Enterprise Linux AppStream EUS (v. 8.2) &#8211; aarch64, noarch, ppc64le, s390x, x86_64<\/p>\n<p dir=\"ltr\">3. Description:<\/p>\n<p dir=\"ltr\">Ruby is an extensible, interpreted, object-oriented, scripting language. It<br \/>\nhas features to process text files and to perform system management tasks.<\/p>\n<p dir=\"ltr\">Security Fix(es):<\/p>\n<p dir=\"ltr\">* rubygem-bundler: Dependencies of gems with explicit source may be<br \/>\ninstalled from a different source (CVE-2020-36327)<\/p>\n<p dir=\"ltr\">* ruby: NUL injection vulnerability of File.fnmatch and File.fnmatch?<br \/>\n(CVE-2019-15845)<\/p>\n<p dir=\"ltr\">* ruby: Regular expression denial of service vulnerability of WEBrick&#8217;s<br \/>\nDigest authentication (CVE-2019-16201)<\/p>\n<p dir=\"ltr\">* ruby: Code injection via command argument of Shell#test \/ Shell#[]\n(CVE-2019-16255)<\/p>\n<p dir=\"ltr\">* rubygem-json: Unsafe object creation vulnerability in JSON<br \/>\n(CVE-2020-10663)<\/p>\n<p dir=\"ltr\">* ruby: BasicSocket#read_nonblock method leads to information disclosure<br \/>\n(CVE-2020-10933)<\/p>\n<p dir=\"ltr\">* ruby: Potential HTTP request smuggling in WEBrick (CVE-2020-25613)<\/p>\n<p dir=\"ltr\">* ruby: XML round-trip vulnerability in REXML (CVE-2021-28965)<\/p>\n<p dir=\"ltr\">* rubygem-rdoc: Command injection vulnerability in RDoc (CVE-2021-31799)<\/p>\n<p dir=\"ltr\">* ruby: FTP PASV command response can cause Net::FTP to connect to<br \/>\narbitrary host (CVE-2021-31810)<\/p>\n<p dir=\"ltr\">* ruby: StartTLS stripping vulnerability in Net::IMAP (CVE-2021-32066)<\/p>\n<p dir=\"ltr\">* ruby: Regular expression denial of service vulnerability of Date parsing<br \/>\nmethods (CVE-2021-41817)<\/p>\n<p dir=\"ltr\">* ruby: Cookie prefix spoofing in CGI::Cookie.parse (CVE-2021-41819)<\/p>\n<p dir=\"ltr\">* ruby: HTTP response splitting in WEBrick (CVE-2019-16254)<\/p>\n<p dir=\"ltr\">For more details about the security issue(s), including the impact, a CVSS<br \/>\nscore, acknowledgments, and other related information, refer to the CVE<br \/>\npage(s) listed in the References section.<\/p>\n<p dir=\"ltr\">4. Solution:<\/p>\n<p dir=\"ltr\">For details on how to apply this update, which includes the changes<br \/>\ndescribed in this advisory, refer to:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/articles\/11258<\/p>\n<p dir=\"ltr\">5. Bugs fixed (https:\/\/bugzilla.redhat.com\/):<\/p>\n<p dir=\"ltr\">1773728 &#8211; CVE-2019-16201 ruby: Regular expression denial of service vulnerability of WEBrick&#8217;s Digest authentication<br \/>\n1789407 &#8211; CVE-2019-15845 ruby: NUL injection vulnerability of File.fnmatch and File.fnmatch?<br \/>\n1789556 &#8211; CVE-2019-16254 ruby: HTTP response splitting in WEBrick<br \/>\n1793683 &#8211; CVE-2019-16255 ruby: Code injection via command argument of Shell#test \/ Shell#[]\n1827500 &#8211; CVE-2020-10663 rubygem-json: Unsafe object creation vulnerability in JSON<br \/>\n1833291 &#8211; CVE-2020-10933 ruby: BasicSocket#read_nonblock method leads to information disclosure<br \/>\n1883623 &#8211; CVE-2020-25613 ruby: Potential HTTP request smuggling in WEBrick<br \/>\n1947526 &#8211; CVE-2021-28965 ruby: XML round-trip vulnerability in REXML<br \/>\n1958999 &#8211; CVE-2020-36327 rubygem-bundler: Dependencies of gems with explicit source may be installed from a different source<br \/>\n1980126 &#8211; CVE-2021-31810 ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host<br \/>\n1980128 &#8211; CVE-2021-32066 ruby: StartTLS stripping vulnerability in Net::IMAP<br \/>\n1980132 &#8211; CVE-2021-31799 rubygem-rdoc: Command injection vulnerability in RDoc<br \/>\n2025104 &#8211; CVE-2021-41817 ruby: Regular expression denial of service vulnerability of Date parsing methods<br \/>\n2026757 &#8211; CVE-2021-41819 ruby: Cookie prefix spoofing in CGI::Cookie.parse<\/p>\n<p dir=\"ltr\">6. Package List:<\/p>\n<p dir=\"ltr\">Red Hat Enterprise Linux AppStream EUS (v. 8.2):<\/p>\n<p dir=\"ltr\">Source:<br \/>\nruby-2.6.9-107.module+el8.2.0+14086+86d863af.src.rpm<br \/>\nrubygem-abrt-0.3.0-4.module+el8.1.0+3653+beb38eb0.src.rpm<br \/>\nrubygem-bson-4.5.0-1.module+el8.1.0+3653+beb38eb0.src.rpm<br \/>\nrubygem-mongo-2.8.0-1.module+el8.1.0+3653+beb38eb0.src.rpm<br \/>\nrubygem-mysql2-0.5.2-1.module+el8.1.0+3653+beb38eb0.src.rpm<br \/>\nrubygem-pg-1.1.4-1.module+el8.1.0+3653+beb38eb0.src.rpm<\/p>\n<p dir=\"ltr\">aarch64:<br \/>\nruby-2.6.9-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nruby-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nruby-debugsource-2.6.9-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nruby-devel-2.6.9-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nruby-libs-2.6.9-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nruby-libs-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-bigdecimal-1.4.1-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-bigdecimal-debuginfo-1.4.1-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-bson-4.5.0-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-bson-debuginfo-4.5.0-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-bson-debugsource-4.5.0-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-io-console-0.4.7-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-io-console-debuginfo-0.4.7-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-json-2.1.0-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-json-debuginfo-2.1.0-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-mysql2-0.5.2-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-mysql2-debuginfo-0.5.2-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-mysql2-debugsource-0.5.2-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-openssl-2.1.2-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-openssl-debuginfo-2.1.2-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-pg-1.1.4-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-pg-debuginfo-1.1.4-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-pg-debugsource-1.1.4-1.module+el8.1.0+3653+beb38eb0.aarch64.rpm<br \/>\nrubygem-psych-3.1.0-107.module+el8.2.0+14086+86d863af.aarch64.rpm<br \/>\nrubygem-psych-debuginfo-3.1.0-107.module+el8.2.0+14086+86d863af.aarch64.rpm<\/p>\n<p dir=\"ltr\">noarch:<br \/>\nruby-doc-2.6.9-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-abrt-0.3.0-4.module+el8.1.0+3653+beb38eb0.noarch.rpm<br \/>\nrubygem-abrt-doc-0.3.0-4.module+el8.1.0+3653+beb38eb0.noarch.rpm<br \/>\nrubygem-bson-doc-4.5.0-1.module+el8.1.0+3653+beb38eb0.noarch.rpm<br \/>\nrubygem-bundler-1.17.2-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-did_you_mean-1.3.0-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-irb-1.0.0-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-minitest-5.11.3-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-mongo-2.8.0-1.module+el8.1.0+3653+beb38eb0.noarch.rpm<br \/>\nrubygem-mongo-doc-2.8.0-1.module+el8.1.0+3653+beb38eb0.noarch.rpm<br \/>\nrubygem-mysql2-doc-0.5.2-1.module+el8.1.0+3653+beb38eb0.noarch.rpm<br \/>\nrubygem-net-telnet-0.2.0-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-pg-doc-1.1.4-1.module+el8.1.0+3653+beb38eb0.noarch.rpm<br \/>\nrubygem-power_assert-1.1.3-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-rake-12.3.3-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-rdoc-6.1.2.1-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-test-unit-3.2.9-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygem-xmlrpc-0.3.0-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygems-3.0.3.1-107.module+el8.2.0+14086+86d863af.noarch.rpm<br \/>\nrubygems-devel-3.0.3.1-107.module+el8.2.0+14086+86d863af.noarch.rpm<\/p>\n<p dir=\"ltr\">ppc64le:<br \/>\nruby-2.6.9-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nruby-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nruby-debugsource-2.6.9-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nruby-devel-2.6.9-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nruby-libs-2.6.9-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nruby-libs-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-bigdecimal-1.4.1-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-bigdecimal-debuginfo-1.4.1-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-bson-4.5.0-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-bson-debuginfo-4.5.0-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-bson-debugsource-4.5.0-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-io-console-0.4.7-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-io-console-debuginfo-0.4.7-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-json-2.1.0-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-json-debuginfo-2.1.0-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-mysql2-0.5.2-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-mysql2-debuginfo-0.5.2-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-mysql2-debugsource-0.5.2-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-openssl-2.1.2-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-openssl-debuginfo-2.1.2-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-pg-1.1.4-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-pg-debuginfo-1.1.4-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-pg-debugsource-1.1.4-1.module+el8.1.0+3653+beb38eb0.ppc64le.rpm<br \/>\nrubygem-psych-3.1.0-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<br \/>\nrubygem-psych-debuginfo-3.1.0-107.module+el8.2.0+14086+86d863af.ppc64le.rpm<\/p>\n<p dir=\"ltr\">s390x:<br \/>\nruby-2.6.9-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nruby-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nruby-debugsource-2.6.9-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nruby-devel-2.6.9-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nruby-libs-2.6.9-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nruby-libs-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-bigdecimal-1.4.1-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-bigdecimal-debuginfo-1.4.1-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-bson-4.5.0-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-bson-debuginfo-4.5.0-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-bson-debugsource-4.5.0-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-io-console-0.4.7-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-io-console-debuginfo-0.4.7-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-json-2.1.0-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-json-debuginfo-2.1.0-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-mysql2-0.5.2-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-mysql2-debuginfo-0.5.2-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-mysql2-debugsource-0.5.2-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-openssl-2.1.2-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-openssl-debuginfo-2.1.2-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-pg-1.1.4-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-pg-debuginfo-1.1.4-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-pg-debugsource-1.1.4-1.module+el8.1.0+3653+beb38eb0.s390x.rpm<br \/>\nrubygem-psych-3.1.0-107.module+el8.2.0+14086+86d863af.s390x.rpm<br \/>\nrubygem-psych-debuginfo-3.1.0-107.module+el8.2.0+14086+86d863af.s390x.rpm<\/p>\n<p dir=\"ltr\">x86_64:<br \/>\nruby-2.6.9-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nruby-2.6.9-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nruby-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nruby-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nruby-debugsource-2.6.9-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nruby-debugsource-2.6.9-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nruby-devel-2.6.9-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nruby-devel-2.6.9-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nruby-libs-2.6.9-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nruby-libs-2.6.9-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nruby-libs-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nruby-libs-debuginfo-2.6.9-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-bigdecimal-1.4.1-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-bigdecimal-1.4.1-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-bigdecimal-debuginfo-1.4.1-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-bigdecimal-debuginfo-1.4.1-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-bson-4.5.0-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-bson-debuginfo-4.5.0-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-bson-debugsource-4.5.0-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-io-console-0.4.7-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-io-console-0.4.7-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-io-console-debuginfo-0.4.7-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-io-console-debuginfo-0.4.7-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-json-2.1.0-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-json-2.1.0-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-json-debuginfo-2.1.0-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-json-debuginfo-2.1.0-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-mysql2-0.5.2-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-mysql2-debuginfo-0.5.2-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-mysql2-debugsource-0.5.2-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-openssl-2.1.2-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-openssl-2.1.2-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-openssl-debuginfo-2.1.2-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-openssl-debuginfo-2.1.2-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-pg-1.1.4-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-pg-debuginfo-1.1.4-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-pg-debugsource-1.1.4-1.module+el8.1.0+3653+beb38eb0.x86_64.rpm<br \/>\nrubygem-psych-3.1.0-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-psych-3.1.0-107.module+el8.2.0+14086+86d863af.x86_64.rpm<br \/>\nrubygem-psych-debuginfo-3.1.0-107.module+el8.2.0+14086+86d863af.i686.rpm<br \/>\nrubygem-psych-debuginfo-3.1.0-107.module+el8.2.0+14086+86d863af.x86_64.rpm<\/p>\n<p dir=\"ltr\">These packages are GPG signed by Red Hat for security. Our key and<br \/>\ndetails on how to verify the signature are available from<br \/>\nhttps:\/\/access.redhat.com\/security\/team\/key\/<\/p>\n<p dir=\"ltr\">7. References:<\/p>\n<p dir=\"ltr\">https:\/\/access.redhat.com\/security\/cve\/CVE-2019-15845<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-16201<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-16254<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2019-16255<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-10663<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-10933<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-25613<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2020-36327<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-28965<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-31799<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-31810<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-32066<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-41817<br \/>\nhttps:\/\/access.redhat.com\/security\/cve\/CVE-2021-41819<br \/>\nhttps:\/\/access.redhat.com\/security\/updates\/classification\/#important<br \/>\nhttps:\/\/access.redhat.com\/articles\/6206172<\/p>\n<p dir=\"ltr\">8. Contact:<\/p>\n<p dir=\"ltr\">The Red Hat security contact is &lt;secalert@redhat.com&gt;. More contact<br \/>\ndetails at https:\/\/access.redhat.com\/security\/team\/contact\/<\/p>\n<p dir=\"ltr\">Copyright 2022 Red Hat, Inc.<br \/>\n&#8212;&#8211;BEGIN PGP SIGNATURE&#8212;&#8211;<br \/>\nVersion: GnuPG v1<\/p>\n<p dir=\"ltr\">iQIVAwUBYhNmodzjgjWX9erEAQislRAAmu+BcHScvr7rugItwkGVllOK1gWCkdxC<br \/>\nDNJWU+G4tZadfBBAMLdpuoC8bFL1YnK21k5OE1uwPqsTgbUH+IvXB88TcaDTRSFj<br \/>\n4Lqv\/fj8KVlYDNVia4CojWo+60wZTcmdT+Hyklq+qhwj8SbVKhOJ5WtWw\/LhJJPf<br \/>\n\/HqIooYnq0i0ScbXy1UdyW3wmcv\/bSv2QNAuEuWSjxd8OmOg2eYlV7deWw+zQNOU<br \/>\nabrXZLIKCIGUSxi9T29KLTjuej1g9XEgZMZ2l1gpIRghYJYmqgQ4kQUoCFNyj7W6<br \/>\nAdoX8KjhRg9y1rrv0ZbAoVXQ5VXEz5ykcA0soWb6wSDDBTsvDWoUMKnJs1TzLaN\/<br \/>\nkYDHCtMSg0vmyTCnhnbaC2T0sR7j7YHVhCiviKVMHfTAD5XXpbcb+wLR99JQgOU\/<br \/>\nAvIdu2\/H8Q9eyrUy8deeY3S7bXaSwWV0+jww56kODkZUJa5XbDM18Te4NEemlYCt<br \/>\nC9pMpAaTHEuKJw6JD2+RrFAN\/PZG7Ca3KZczP33DTN0pBGb+b5tXrj8wLTt+K2VC<br \/>\n1q4qAWCoiFOyI+AIj5mkUKCN1Bko9cBb+hBXh3K4yVnTN1aE3snYSkwuxoUDKC7P<br \/>\nm6FYrzkJbakDkibF2vjImyxkiHKktI7RT3spJ5P6V9usbUr4kwQ+sqpJHIleis8C<br \/>\niGAmwygvmQg=<br \/>\n=OFRq<br \/>\n&#8212;&#8211;END PGP SIGNATURE&#8212;&#8211;<\/p>\n<p dir=\"ltr\">&#8212;<br \/>\nRHSA-announce mailing list<br \/>\nRHSA-announce@redhat.com<br \/>\nhttps:\/\/listman.redhat.com\/mailman\/listinfo\/rhsa-announce<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8212;&#8211;BEGIN PGP SIGNED MESSAGE&#8212;&#8211; Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: ruby:2.6 security update Advisory ID: RHSA-2022:0582-01 Product: Red Hat Enterprise Linux Advisory URL: https:\/\/access.redhat.com\/errata\/RHSA-2022:0582 Issue date: 2022-02-21 CVE Names: CVE-2019-15845 CVE-2019-16201 CVE-2019-16254 CVE-2019-16255 CVE-2020-10663 CVE-2020-10933 CVE-2020-25613 CVE-2020-36327 CVE-2021-28965 CVE-2021-31799 CVE-2021-31810 CVE-2021-32066 CVE-2021-41817 CVE-2021-41819 ===================================================================== 1. Summary: An update for the ruby:2.6 module &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-20921","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/20921","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=20921"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/20921\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=20921"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=20921"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=20921"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}