Ubuntu Security Notice 621-1 – Drew Yao discovered several vulnerabilities in Ruby which lead to integer overflows. If a user or automated system were tricked into running a malicious script, an attacker could cause a denial of service or execute arbitrary code with the privileges of the user invoking the program. Drew Yao discovered that Ruby did not sanitize its input when using ALLOCA. If a user or automated system were tricked into running a malicious script, an attacker could cause a denial of service via memory corruption.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/67733/USN-621-1.txt
Source: https://packetstormsecurity.com/files/67733/Ubuntu-Security-Notice-621-1.html