VYPR

rpm package

almalinux/rubygem-psych

pkg:rpm/almalinux/rubygem-psych

Vulnerabilities (42)

  • CVE-2020-36327HigApr 29, 2021
    affected < 3.1.0-137.module_el8.4.0+2515+f744ca41fixed 3.1.0-137.module_el8.4.0+2515+f744ca41

    Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another

  • CVE-2019-19012CriNov 17, 2019
    affected < 3.0.2-114.module_el8.10.0+3991+5e651d4efixed 3.0.2-114.module_el8.10.0+3991+5e651d4e

    An integer overflow in the search_in_range function in regexec.c in Oniguruma 6.x before 6.9.4_rc2 leads to an out-of-bounds read, in which the offset of this read is under the control of an attacker. (This only affects the 32-bit compiled version). Remote attackers can cause a d

Page 3 of 3