ELA-1148-1 ruby2.1 security update

multiple vulnerabilities

2024-08-13
Packageruby2.1
Version2.1.5-2+deb8u14 (jessie)
Related CVEs CVE-2016-2338 CVE-2021-28965 CVE-2021-33621 CVE-2021-41817 CVE-2022-28739 CVE-2023-28756 CVE-2024-27281 CVE-2024-27282


Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in denial-of-service (DoS), information leak, HTTP response splitting, XML round-trip issues, and remote code execution.

This release also provide follow-up fixes for CVE-2016-2338 (ELA-1148-1) and CVE-2021-41817 (ELA-531-1).



For Debian 8 jessie, these problems have been fixed in version 2.1.5-2+deb8u14.

We recommend that you upgrade your ruby2.1 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.