rpm package
almalinux/rubygem-racc
pkg:rpm/almalinux/rubygem-racc
Vulnerabilities (23)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2024-27282 | Med | 6.6 | < 1.7.3-2.module_el8.10.0+3855+767cb125 | 1.7.3-2.module_el8.10.0+3855+767cb125 | May 14, 2024 | An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2 | |
| CVE-2024-27281 | Med | 4.5 | < 1.7.3-2.module_el8.10.0+3855+767cb125 | 1.7.3-2.module_el8.10.0+3855+767cb125 | May 14, 2024 | An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the cl | |
| CVE-2024-27280 | Cri | 9.8 | < 1.7.3-2.module_el8.10.0+3855+767cb125 | 1.7.3-2.module_el8.10.0+3855+767cb125 | May 14, 2024 | A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0. |
- affected < 1.7.3-2.module_el8.10.0+3855+767cb125fixed 1.7.3-2.module_el8.10.0+3855+767cb125
An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitrary heap data relative to the start of the text, including pointers and sensitive strings. The fixed versions are 3.0.7, 3.1.5, 3.2
- affected < 1.7.3-2.module_el8.10.0+3855+767cb125fixed 1.7.3-2.module_el8.10.0+3855+767cb125
An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in RDoc) as a YAML file, object injection and resultant remote code execution are possible because there are no restrictions on the cl
- affected < 1.7.3-2.module_el8.10.0+3855+767cb125fixed 1.7.3-2.module_el8.10.0+3855+767cb125
A buffer-overread issue was discovered in StringIO 3.0.1, as distributed in Ruby 3.0.x through 3.0.6 and 3.1.x through 3.1.4. The ungetbyte and ungetc methods on a StringIO can read past the end of a string, and a subsequent call to StringIO.gets may return the memory value. 3.0.
Page 2 of 2