Amazon Linux 2 Security Advisory: ALASRUBY2.6-2023-005
Advisory Release Date: 2023-08-21 20:59 Pacific
Advisory Updated Date: 2023-09-25 22:02 Pacific
An operating system command injection flaw was found in RDoc. Using the rdoc command to generate documentation for a malicious Ruby source code could lead to execution of arbitrary commands with the privileges of the user running rdoc. (CVE-2021-31799)
Affected Packages:
ruby
Note:
This advisory is applicable to Amazon Linux 2 - Ruby2.6 Extra. Visit this page to learn more about Amazon Linux 2 (AL2) Extras and this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update ruby to update your system.
aarch64:
ruby-2.6.7-126.amzn2.0.2.aarch64
ruby-devel-2.6.7-126.amzn2.0.2.aarch64
ruby-libs-2.6.7-126.amzn2.0.2.aarch64
rubygem-bigdecimal-1.4.1-126.amzn2.0.2.aarch64
rubygem-io-console-0.4.7-126.amzn2.0.2.aarch64
rubygem-json-2.1.0-126.amzn2.0.2.aarch64
rubygem-openssl-2.1.2-126.amzn2.0.2.aarch64
rubygem-psych-3.1.0-126.amzn2.0.2.aarch64
ruby-debuginfo-2.6.7-126.amzn2.0.2.aarch64
i686:
ruby-2.6.7-126.amzn2.0.2.i686
ruby-devel-2.6.7-126.amzn2.0.2.i686
ruby-libs-2.6.7-126.amzn2.0.2.i686
rubygem-bigdecimal-1.4.1-126.amzn2.0.2.i686
rubygem-io-console-0.4.7-126.amzn2.0.2.i686
rubygem-json-2.1.0-126.amzn2.0.2.i686
rubygem-openssl-2.1.2-126.amzn2.0.2.i686
rubygem-psych-3.1.0-126.amzn2.0.2.i686
ruby-debuginfo-2.6.7-126.amzn2.0.2.i686
noarch:
rubygems-3.0.3.1-126.amzn2.0.2.noarch
rubygems-devel-3.0.3.1-126.amzn2.0.2.noarch
rubygem-rake-12.3.3-126.amzn2.0.2.noarch
rubygem-irb-1.0.0-126.amzn2.0.2.noarch
rubygem-rdoc-6.1.2-126.amzn2.0.2.noarch
ruby-doc-2.6.7-126.amzn2.0.2.noarch
rubygem-did_you_mean-1.3.0-126.amzn2.0.2.noarch
rubygem-minitest-5.11.3-126.amzn2.0.2.noarch
rubygem-power_assert-1.1.3-126.amzn2.0.2.noarch
rubygem-net-telnet-0.2.0-126.amzn2.0.2.noarch
rubygem-test-unit-3.2.9-126.amzn2.0.2.noarch
rubygem-xmlrpc-0.3.0-126.amzn2.0.2.noarch
rubygem-bundler-1.17.2-126.amzn2.0.2.noarch
src:
ruby-2.6.7-126.amzn2.0.2.src
x86_64:
ruby-2.6.7-126.amzn2.0.2.x86_64
ruby-devel-2.6.7-126.amzn2.0.2.x86_64
ruby-libs-2.6.7-126.amzn2.0.2.x86_64
rubygem-bigdecimal-1.4.1-126.amzn2.0.2.x86_64
rubygem-io-console-0.4.7-126.amzn2.0.2.x86_64
rubygem-json-2.1.0-126.amzn2.0.2.x86_64
rubygem-openssl-2.1.2-126.amzn2.0.2.x86_64
rubygem-psych-3.1.0-126.amzn2.0.2.x86_64
ruby-debuginfo-2.6.7-126.amzn2.0.2.x86_64