CVE-2019-8320

medium
Published 2019-03-05 ยท Modified 2019-11-05
CVSS v3
โ€”
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
5.5

Description

RHBA-2019:3384: ruby:2.5 bug fix and enhancement update (Moderate)

Predictions

Exploit likelihood
30%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Red Hat Errata โ€” Red Hat Inc. ยท View original โ†— ยท Open-Errata-API

Description rubygems: Delete directory using symlink when decompressing tar CVSS v3: 7.4 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H) Errata / fixed releases ProductPackageAdvisoryReleased CloudForms Management Engine 5.10cfme-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z CloudForms Management Engine 5.10cfme-amazon-smartstate-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Zโ€ฆ

Description

rubygems: Delete directory using symlink when decompressing tar

CVSS v3: 7.4 (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H)

Errata / fixed releases

ProductPackageAdvisoryReleased
CloudForms Management Engine 5.10cfme-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z
CloudForms Management Engine 5.10cfme-amazon-smartstate-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z
CloudForms Management Engine 5.10cfme-appliance-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z
CloudForms Management Engine 5.10cfme-gemset-0:5.10.5.1-1.el7cfRHSA-2019:14292019-06-11T00:00:00Z
CloudForms Management Engine 5.10ruby-0:2.4.6-91.el7cfRHSA-2019:14292019-06-11T00:00:00Z
Red Hat Enterprise Linux 8ruby:2.5-8010020190711131821.cdc1202bRHBA-2019:33842019-11-05T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 6rh-ruby24-ruby-0:2.4.6-92.el6RHSA-2019:11502019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-ruby25-ruby-0:2.5.5-7.el7RHSA-2019:11482019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7rh-ruby24-ruby-0:2.4.6-92.el7RHSA-2019:11502019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSrh-ruby25-ruby-0:2.5.5-7.el7RHSA-2019:11482019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSrh-ruby24-ruby-0:2.4.6-92.el7RHSA-2019:11502019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-ruby25-ruby-0:2.5.5-7.el7RHSA-2019:11482019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSrh-ruby24-ruby-0:2.4.6-92.el7RHSA-2019:11502019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-ruby25-ruby-0:2.5.5-7.el7RHSA-2019:11482019-05-13T00:00:00Z
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSrh-ruby24-ruby-0:2.4.6-92.el7RHSA-2019:11502019-05-13T00:00:00Z

Package state

ProductPackageState
Red Hat Enterprise Linux 6rubygemsNot affected
Red Hat Enterprise Linux 7rubyNot affected
Red Hat Software Collectionsrh-ruby23-rubyWill not fix
Red Hat Software Collectionsrh-ruby26-rubyNot affected

Apply commands

bash fix
Apply RHSA-2019:1429 for CloudForms Management Engine 5.10
yum update -y cfme
# or:
dnf upgrade -y cfme

Affected

VendorProductVersion
redhatRed Hat Enterprise Linux 6Not affected
redhatRed Hat Enterprise Linux 7Not affected
redhatRed Hat Software CollectionsNot affected

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
โ€” Affected โ€”
almalinux AlmaLinux Fixed 1 release
VersionStatusFixed in
8 Fixed rubygem-abrt-doc-0.3.0-4.module_el8.5.0+2623+08a8ba32.noarch.rpm
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 9.1.17.0-3
sid Fixed 9.1.17.0-3
forky Fixed 9.1.17.0-3
bullseye Fixed 3.2.0~rc.1-1
bookworm Fixed 9.1.17.0-3
redhat Red Hat Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”
rockylinux Rocky Linux Fixed 1 release
VersionStatusFixed in
8 Fixed โ€”

Package impact

EcosystemPackageVulnerableFixed
ruby RubyGemsrubygems-update!< 2.7.6||<>= 3.0.3>= 3.0.3
ruby RubyGemsrubygems-update>=2.7.6,<2.7.92.7.9
ruby RubyGemsrubygems-update>=3.0.0,<3.0.33.0.3

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.