{"id":"ALSA-2019:1972","summary":"Important: ruby:2.5 security update","details":"Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.\n\nSecurity Fix(es):\n\n* rubygems: Installing a malicious gem may lead to arbitrary code execution (CVE-2019-8324)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.","modified":"2026-02-04T03:59:24.361118Z","published":"2019-07-30T11:16:25Z","related":["CVE-2019-8324"],"references":[{"type":"ADVISORY","url":"https://errata.almalinux.org/8/ALSA-2019-1972.html"},{"type":"REPORT","url":"https://vulners.com/cve/CVE-2019-8324"}],"affected":[{"package":{"name":"rubygem-abrt","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-abrt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.0-4.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-abrt","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-abrt"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.0-4.module_el8.5.0+2623+08a8ba32"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-abrt-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-abrt-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.0-4.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-abrt-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-abrt-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.3.0-4.module_el8.5.0+2623+08a8ba32"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-bson","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-bson"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0-2.module_el8.5.0+2625+ec418553"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-bson","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-bson"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0-2.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-bson-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-bson-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0-2.module_el8.5.0+2625+ec418553"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-bson-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-bson-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.0-2.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-mongo","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-mongo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.1-2.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-mongo","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-mongo"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.1-2.module_el8.5.0+2625+ec418553"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-mongo-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-mongo-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.1-2.module_el8.5.0+2625+ec418553"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-mongo-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-mongo-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.5.1-2.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-mysql2","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-mysql2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.10-4.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-mysql2","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-mysql2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.10-4.module_el8.5.0+2625+ec418553"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-mysql2-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-mysql2-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.10-4.module_el8.5.0+2625+ec418553"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-mysql2-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-mysql2-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.4.10-4.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-pg","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-pg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0-2.module_el8.5.0+2625+ec418553"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-pg","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-pg"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0-2.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-pg-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-pg-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0-2.module_el8.5.0+2625+ec418553"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}},{"package":{"name":"rubygem-pg-doc","ecosystem":"AlmaLinux:8","purl":"pkg:rpm/almalinux/rubygem-pg-doc"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.0-2.module_el8.5.0+259+8cec6917"}]}],"database_specific":{"source":"https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux8/ALSA-2019:1972.json"}}],"schema_version":"1.7.3"}