Skip to content

Commit 1cb1c83

Browse files
jasnowpostmodern
authored andcommitted
GHSA SYNC: 4 related 2008 ruby modified advisories
1 parent 1f1b9c8 commit 1cb1c83

File tree

4 files changed

+71
-5
lines changed

4 files changed

+71
-5
lines changed

rubies/ruby/CVE-2008-3655.yml

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,7 @@
11
---
22
engine: ruby
33
cve: 2008-3655
4+
ghsa: p524-ppf2-w36w
45
url: https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
56
title: Ruby multiple insufficient safe mode restrictions
67
date: 2008-08-08
@@ -16,3 +17,19 @@ patched_versions:
1617
- "~> 1.8.6.287"
1718
- "~> 1.8.7.72"
1819
- ">= 1.9.0"
20+
related:
21+
url:
22+
- https://nvd.nist.gov/vuln/detail/CVE-2008-3655
23+
- https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby
24+
- https://www.ruby-lang.org/en/news/2008/08/11/ruby-1-8-7-p72-and-1-8-6-p287-released
25+
- https://security.gentoo.org/glsa/200812-17
26+
- https://www.us-cert.gov/cas/techalerts/TA09-133A.html
27+
- https://support.apple.com/en-us/104129
28+
- https://web.archive.org/web/20090517222231/https://lists.apple.com/archives/security-announce/2009/May/msg00002.html
29+
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494401
30+
- https://www.debian.org/security/2008/dsa-1652
31+
- https://www.debian.org/security/2008/dsa-1651
32+
- https://lists.ubuntu.com/archives/ubuntu-security-announce/2008-October/000765.html
33+
- https://support.avaya.com/elmodocs2/security/ASA-2008-424.htm
34+
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44369
35+
- https://github.com/advisories/GHSA-p524-ppf2-w36w

rubies/ruby/CVE-2008-3656.yml

Lines changed: 20 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,10 @@
11
---
22
engine: ruby
33
cve: 2008-3656
4-
url: https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
5-
title: Ruby WEBrick::HTTP::DefaultFileHandler DoS
6-
date: 2008-08-08
4+
ghsa: 823x-6r7f-v9x6
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2008-3656
6+
title: Algorithmic complexity vulnerability in the WEBrick
7+
date: 2008-08-12
78
description: |
89
Algorithmic complexity vulnerability in the
910
WEBrick::HTTPUtils.split_header_value function in
@@ -17,3 +18,19 @@ patched_versions:
1718
- "~> 1.8.6.287"
1819
- "~> 1.8.7.72"
1920
- ">= 1.9.0"
21+
related:
22+
url:
23+
- https://nvd.nist.gov/vuln/detail/CVE-2008-3656
24+
- https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby
25+
- https://www.ruby-lang.org/en/news/2008/08/11/ruby-1-8-7-p72-and-1-8-6-p287-released
26+
- https://security.gentoo.org/glsa/200812-17
27+
- https://www.us-cert.gov/cas/techalerts/TA09-133A.html
28+
- https://support.apple.com/en-us/104129
29+
- https://web.archive.org/web/20090517222231/https://lists.apple.com/archives/security-announce/2009/May/msg00002.html
30+
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494401
31+
- https://www.debian.org/security/2008/dsa-1652
32+
- https://www.debian.org/security/2008/dsa-1651
33+
- https://lists.ubuntu.com/archives/ubuntu-security-announce/2008-October/000765.html
34+
- https://support.avaya.com/elmodocs2/security/ASA-2008-424.htm
35+
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44371
36+
- https://github.com/advisories/GHSA-823x-6r7f-v9x6

rubies/ruby/CVE-2008-3657.yml

Lines changed: 18 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
22
engine: ruby
33
cve: 2008-3657
4-
url: https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
4+
ghsa: 5f6v-fgcw-j5px
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2008-3657
56
title: Ruby missing "taintness" checks in dl module
67
date: 2008-08-08
78
description: |
@@ -14,3 +15,19 @@ patched_versions:
1415
- "~> 1.8.6.287"
1516
- "~> 1.8.7.72"
1617
- ">= 1.9.0"
18+
related:
19+
url:
20+
- https://nvd.nist.gov/vuln/detail/CVE-2008-3657
21+
- https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby
22+
- https://www.ruby-lang.org/en/news/2008/08/11/ruby-1-8-7-p72-and-1-8-6-p287-released
23+
- https://security.gentoo.org/glsa/200812-17
24+
- https://www.us-cert.gov/cas/techalerts/TA09-133A.html
25+
- https://support.apple.com/en-us/104129
26+
- https://web.archive.org/web/20090517222231/https://lists.apple.com/archives/security-announce/2009/May/msg00002.html
27+
- https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=494401
28+
- https://www.debian.org/security/2008/dsa-1652
29+
- https://www.debian.org/security/2008/dsa-1651
30+
- https://lists.ubuntu.com/archives/ubuntu-security-announce/2008-October/000765.html
31+
- https://support.avaya.com/elmodocs2/security/ASA-2008-424.htm
32+
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44372
33+
- https://github.com/advisories/GHSA-5f6v-fgcw-j5px

rubies/ruby/CVE-2008-3905.yml

Lines changed: 16 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,8 @@
11
---
22
engine: ruby
33
cve: 2008-3905
4-
url: https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby/
4+
ghsa: vwcj-mf69-7rfw
5+
url: https://nvd.nist.gov/vuln/detail/CVE-2008-3905
56
title: ruby -- DNS spoofing vulnerability in resolv.rb
67
date: 2008-05-05
78
description: |
@@ -15,3 +16,17 @@ patched_versions:
1516
- "~> 1.8.6.287"
1617
- "~> 1.8.7.72"
1718
- ">= 1.9.0"
19+
related:
20+
url:
21+
- https://nvd.nist.gov/vuln/detail/CVE-2008-3905
22+
- https://www.ruby-lang.org/en/news/2008/08/08/multiple-vulnerabilities-in-ruby
23+
- https://www.ruby-lang.org/en/news/2008/08/11/ruby-1-8-7-p72-and-1-8-6-p287-released
24+
- https://www.openwall.com/lists/oss-security/2008/09/03/3
25+
- https://www.openwall.com/lists/oss-security/2008/09/04/9
26+
- https://www.slackware.com/security/viewer.php?l=slackware-security&y=2008&m=slackware-security.371754
27+
- https://www.debian.org/security/2008/dsa-1652
28+
- https://www.debian.org/security/2008/dsa-1651
29+
30+
- https://support.avaya.com/elmodocs2/security/ASA-2008-424.htm
31+
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45935
32+
- https://github.com/advisories/GHSA-vwcj-mf69-7rfw

0 commit comments

Comments
 (0)