Security update for ruby2.5
This update for ruby2.5 to version 2.5.8 fixes the following issues:
- CVE-2020-10663: Unsafe Object Creation Vulnerability in JSON (bsc#1167244).
- CVE-2020-10933: Heap exposure vulnerability in the socket library (bsc#1168938).
This update was imported from the SUSE:SLE-15:Update update project.
-
Submitted by
Marcus Rueckert (darix)
Fixed bugs
bnc#1168938
VUL-0: CVE-2020-10933: ruby2.5: Heap exposure vulnerability in the socket library
bnc#1167244
VUL-1: CVE-2020-10663: rubygem-json: Unsafe Object Creation Vulnerability in JSON