{"affected":[{"ecosystem_specific":{"binaries":[{"libruby2_1-2_1":"2.1.9-15.1","ruby2.1":"2.1.9-15.1","ruby2.1-stdlib":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP1","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libruby2_1-2_1":"2.1.9-15.1","ruby2.1":"2.1.9-15.1","ruby2.1-stdlib":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Desktop 12 SP2","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Desktop%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libruby2_1-2_1":"2.1.9-15.1","ruby2.1":"2.1.9-15.1","ruby2.1-stdlib":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for Raspberry Pi 12 SP2","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Server%20for%20Raspberry%20Pi%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ruby2.1-devel":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP1","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"ruby2.1-devel":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Software Development Kit 12 SP2","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libruby2_1-2_1":"2.1.9-15.1","ruby2.1":"2.1.9-15.1","ruby2.1-stdlib":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP1","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libruby2_1-2_1":"2.1.9-15.1","ruby2.1":"2.1.9-15.1","ruby2.1-stdlib":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP1","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP1"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libruby2_1-2_1":"2.1.9-15.1","ruby2.1":"2.1.9-15.1","ruby2.1-stdlib":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server 12 SP2","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]},{"ecosystem_specific":{"binaries":[{"libruby2_1-2_1":"2.1.9-15.1","ruby2.1":"2.1.9-15.1","ruby2.1-stdlib":"2.1.9-15.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP2","name":"ruby2.1","purl":"pkg:rpm/suse/ruby2.1&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"2.1.9-15.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"\nThis ruby2.1 update to version 2.1.9 fixes the following issues:\n\nSecurity issues fixed:\n- CVE-2016-2339: heap overflow vulnerability in the Fiddle::Function.new'initialize' (bsc#1018808)\n- CVE-2015-7551: Unsafe tainted string usage in Fiddle and DL (bsc#959495)\n- CVE-2015-3900: hostname validation does not work when fetching gems or making API requests (bsc#936032)\n- CVE-2015-1855: Ruby'a OpenSSL extension suffers a vulnerability through overly permissive matching of\n  hostnames (bsc#926974)\n- CVE-2014-4975: off-by-one stack-based buffer overflow in the encodes() function (bsc#887877)\n\nBugfixes:\n- SUSEconnect doesn't handle domain wildcards in no_proxy environment variable properly (bsc#1014863)\n- Segmentation fault after pack & ioctl & unpack (bsc#909695)\n- Ruby:HTTP Header injection in 'net/http' (bsc#986630)\n\nChangeLog:\n- http://svn.ruby-lang.org/repos/ruby/tags/v2_1_9/ChangeLog\n","id":"SUSE-SU-2017:1067-1","modified":"2017-04-20T06:35:59Z","published":"2017-04-20T06:35:59Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2017/suse-su-20171067-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1014863"},{"type":"REPORT","url":"https://bugzilla.suse.com/1018808"},{"type":"REPORT","url":"https://bugzilla.suse.com/887877"},{"type":"REPORT","url":"https://bugzilla.suse.com/909695"},{"type":"REPORT","url":"https://bugzilla.suse.com/926974"},{"type":"REPORT","url":"https://bugzilla.suse.com/936032"},{"type":"REPORT","url":"https://bugzilla.suse.com/959495"},{"type":"REPORT","url":"https://bugzilla.suse.com/986630"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2014-4975"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-1855"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-3900"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2015-7551"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2016-2339"}],"related":["CVE-2014-4975","CVE-2015-1855","CVE-2015-3900","CVE-2015-7551","CVE-2016-2339"],"summary":"Security update for ruby2.1","upstream":["CVE-2014-4975","CVE-2015-1855","CVE-2015-3900","CVE-2015-7551","CVE-2016-2339"]}