安全公告详情

NS-SA-2025-0116

2025-07-25 16:49:52

简介

moderate: unixODBC/ruby security update

严重级别

moderate

主题

An update for unixODBC/ruby is now available for NewStart CGSL MAIN 7.02.
NewStart Security has rated this update as having a security impact of moderate. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.

详细描述

unixODBC:
ruby:


Security Fix(es):
unixODBC: An out-of-bounds stack write flaw was found in unixODBC on 64-bit architectures where the caller has 4 bytes and callee writes 8 bytes. This issue may go unnoticed on little-endian architectures, while big-endian architectures can be broken.(CVE-2024-1013)
unixODBC: bugfix
ruby: A flaw was found in Rubygem RDoc. When parsing .rdoc_options used for configuration in RDoc as a YAML file there are no restrictions on the classes that can be restored. This issue may lead to object injection, resulting in remote code execution.(CVE-2024-27281)
ruby: A flaw was found in the rubygem URI. The URI parser mishandles invalid URLs that have specific characters, which causes an increase in execution time parsing strings to URI objects. This issue may result in a regular expression denial of service (ReDoS).(CVE-2023-36617)
ruby: bugfix


Solution:
For details on how to apply this update, which includes the changes described in this advisory, refer to:
http://security.gd-linux.com/how_to_apply_patch.html
Remember the build tag is 7.02.03B8.

影响组件

  • unixODBC
  • ruby

影响产品

  • CGSL MAIN 7.02

更新包

{"fix":[{"product":"CGSL MAIN 7.02","pkgs":[{"binary":["unixODBC-devel-2.3.11-3.zncgsl7.3.x86_64.rpm","unixODBC-2.3.11-3.zncgsl7.3.x86_64.rpm"],"source":"unixODBC-2.3.11-3.zncgsl7.3.src.rpm"},{"binary":["rubygems-3.3.26-9.zncgsl7.4.noarch.rpm","rubygem-rdoc-6.4.0-9.zncgsl7.4.noarch.rpm","rubygem-psych-4.0.4-9.zncgsl7.4.x86_64.rpm","rubygem-irb-1.4.1-9.zncgsl7.4.noarch.rpm","rubygem-io-console-0.5.11-9.zncgsl7.4.x86_64.rpm","rubygem-bundler-2.3.26-9.zncgsl7.4.noarch.rpm","rubygem-bigdecimal-3.1.1-9.zncgsl7.4.x86_64.rpm","ruby-libs-3.1.4-9.zncgsl7.4.x86_64.rpm","ruby-default-gems-3.1.4-9.zncgsl7.4.noarch.rpm","ruby-3.1.4-9.zncgsl7.4.x86_64.rpm"],"source":"ruby-3.1.4-9.zncgsl7.4.src.rpm"}]}]}

CVE

参考