ruby-2.0.0.648-39.0.2.el7.AXS7

エラータID: AXSA:2025-9910:01

リリース日: 
2025/05/09 Friday - 18:34
題名: 
ruby-2.0.0.648-39.0.2.el7.AXS7
影響のあるチャネル: 
Asianux Server 7 for x86_64
Severity: 
High
Description: 

Ruby is the interpreted scripting language for quick and easy
object-oriented programming. It has many features to process text
files and to do system management tasks (as in Perl). It is simple,
straight-forward, and extensible.

Security Fix(es):

* CVE-2025-27219: fix a potential Denial of Service (DoS) vulnerability in
cookie parsing
* CVE-2025-27220: fix ReDoS vulnerability exists in the escapeElement method
* CVE-2025-27221: fix he URI handling methods (URI.join, URI#merge, URI#+)

CVE(s):
CVE-2024-49761
REXML is an XML toolkit for Ruby. The REXML gem before 3.3.9 has a ReDoS vulnerability when it parses an XML that has many digits between &# and x...; in a hex numeric character reference (&#x...;). This does not happen with Ruby 3.2 or later. Ruby 3.1 is the only affected maintained Ruby. The REXML gem 3.3.9 or later include the patch to fix the vulnerability.
CVE-2025-27219
In the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in the CGI library contains a potential Denial of Service (DoS) vulnerability. The method does not impose any limit on the length of the raw cookie value it processes. This oversight can lead to excessive resource consumption when parsing extremely large cookies.
CVE-2025-27220
In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.
CVE-2025-27221
In the URI gem before 1.0.3 for Ruby, the URI handling methods (URI.join, URI#merge, URI#+) have an inadvertent leakage of authentication credentials because userinfo is retained even after changing the host.

解決策: 

Update packages.

追加情報: 

N/A

ダウンロード: 

Asianux Server 7 for x86_64
  1. ruby-2.0.0.648-39.0.2.el7.AXS7.x86_64.rpm
    MD5: c4ee62807fc323c32d33375e417d7649
    SHA-256: 67bada824d24b98bf802f6c0e2630aa4b12269af011cbe9c092f3ffe0de7d2b0
    Size: 73.79 kB
  2. rubygem-bigdecimal-1.2.0-39.0.2.el7.AXS7.x86_64.rpm
    MD5: 72a7e9614a18162c665e7f5b53e604b7
    SHA-256: 33a3e980a3e116025e9bf43fc13642acc68503730754d9ae26eeebfee60af0cd
    Size: 85.70 kB
  3. rubygem-io-console-0.4.2-39.0.2.el7.AXS7.x86_64.rpm
    MD5: 52e4ca941cb046045e7eba5d1fe24898
    SHA-256: 12f2fe9468f2d8231828861da613c57718150926e9e829a495a324b87e103a70
    Size: 56.74 kB
  4. rubygem-json-1.7.7-39.0.2.el7.AXS7.x86_64.rpm
    MD5: 920cdd6973db4d2e9ed5f99e9960431c
    SHA-256: 5e2b83740bfdd9bc63a5b07c55761c3b0ba4260d60a42fb26dd3cdf99000bf82
    Size: 82.28 kB
  5. rubygem-psych-2.0.0-39.0.2.el7.AXS7.x86_64.rpm
    MD5: 5bc748337e6c126445e45a77932ff605
    SHA-256: 7bf91538aa922c79de93f7b62e87eb8b999d343afe6261fdab74cbe48f2f0373
    Size: 85.17 kB
  6. rubygem-rdoc-4.0.0-39.0.2.el7.AXS7.noarch.rpm
    MD5: 9e9055653f475595f0f8f9453a2d4262
    SHA-256: 3412906900e14affdcc81bc3849c1f2404ca8979eeea839669ece85efa23cabb
    Size: 324.58 kB
  7. rubygems-2.0.14.1-39.0.2.el7.AXS7.noarch.rpm
    MD5: e00b9b4ab239ca8ef965ee32aaffd6a6
    SHA-256: 190dd7fdb78d07ac537c4ace2feb16ae145ed350157ab001a5aab188fba34873
    Size: 216.20 kB
  8. ruby-irb-2.0.0.648-39.0.2.el7.AXS7.noarch.rpm
    MD5: 8bda48be5d0c304fef19f31a77abe083
    SHA-256: 71df2068acdc3724cf752692247524e1f1a78b5c56b55469b7fe65edf1d78ca0
    Size: 94.84 kB
  9. ruby-libs-2.0.0.648-39.0.2.el7.AXS7.i686.rpm
    MD5: 4c1d00399500801a18821cf7da536ea0
    SHA-256: a07e8243b5004139cd5665bb63f494ce2f1ee3fb0cd62ba7c12944907cf29f57
    Size: 2.83 MB
  10. ruby-libs-2.0.0.648-39.0.2.el7.AXS7.x86_64.rpm
    MD5: 465a8545ad777ff6ba56217ccdfb53ea
    SHA-256: f8479f993fc1fad17089f8dbd3dff3bd29a6296422fa725ad1e38f4e5e7a162e
    Size: 2.80 MB