PublicDateAtUSN: 2019-11-20 00:00:00 UTC Candidate: CVE-2019-15845 PublicDate: 2019-11-26 17:15:00 UTC References: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15845 https://www.ruby-lang.org/en/news/2019/10/01/nul-injection-file-fnmatch-cve-2019-15845/ https://hackerone.com/reports/449617 https://ubuntu.com/security/notices/USN-4201-1 Description: Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 mishandles path checking within File.fnmatch functions. Ubuntu-Description: Notes: Mitigation: Bugs: Priority: medium Discovered-by: Assigned-to: leosilva CVSS: nvd: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N [6.5 MEDIUM] Patches_ruby2.5: upstream: https://github.com/ruby/ruby/commit/a0a2640b398cffd351f87d3f6243103add66575b (master) upstream: https://github.com/ruby/ruby/commit/02ea1fdfc70b01189574a4a640eec3c9c81d2417 (2.5.x) upstream_ruby2.5: released (2.5.7-1) precise/esm_ruby2.5: DNE trusty_ruby2.5: ignored (out of standard support) trusty/esm_ruby2.5: DNE xenial_ruby2.5: DNE bionic_ruby2.5: released (2.5.1-1ubuntu1.6) disco_ruby2.5: released (2.5.5-1ubuntu1.1) eoan_ruby2.5: released (2.5.5-4ubuntu2.1) devel_ruby2.5: not-affected Patches_ruby2.3: upstream_ruby2.3: needs-triage precise/esm_ruby2.3: DNE trusty_ruby2.3: ignored (out of standard support) trusty/esm_ruby2.3: DNE xenial_ruby2.3: released (2.3.1-2~ubuntu16.04.14) esm-infra/xenial_ruby2.3: released (2.3.1-2~ubuntu16.04.14) bionic_ruby2.3: DNE disco_ruby2.3: DNE eoan_ruby2.3: DNE devel_ruby2.3: DNE Patches_jruby: upstream_jruby: needs-triage precise/esm_jruby: DNE trusty_jruby: ignored (out of standard support) trusty/esm_jruby: not-affected (code not present) xenial_jruby: not-affected (code not present) bionic_jruby: not-affected (code not present) disco_jruby: not-affected (code not present) eoan_jruby: not-affected (code not present) devel_jruby: not-affected (code not present)