CVE-2019-15845
26.11.2019, 17:15
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ruby-lang | ruby | 2.4.0 ≤ 𝑥 ≤ 2.4.7 |
| ruby-lang | ruby | 2.5.0 ≤ 𝑥 ≤ 2.5.6 |
| ruby-lang | ruby | 2.6.0 ≤ 𝑥 ≤ 2.6.4 |
| canonical | ubuntu_linux | 16.04 |
| canonical | ubuntu_linux | 18.04 |
| canonical | ubuntu_linux | 19.04 |
| canonical | ubuntu_linux | 19.10 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|
| jruby |
| ||||||||||
| ruby2.3 |
| ||||||||||
| ruby2.5 |
|
References