UbuntuUpdates.org

Package "ruby3.0-dev"

Name: ruby3.0-dev

Description:

Header files for compiling extension modules for the Ruby 3.0

Latest version: 3.0.2-7ubuntu2.8
Release: jammy (22.04)
Level: security
Repository: main
Head package: ruby3.0
Homepage: https://www.ruby-lang.org/

Links


Download "ruby3.0-dev"


Other versions of "ruby3.0-dev" in Jammy

Repository Area Version
updates main 3.0.2-7ubuntu2.8

Changelog

Version: 3.0.2-7ubuntu2.1 2022-06-06 20:06:22 UTC

  ruby3.0 (3.0.2-7ubuntu2.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Double free
    - debian/patches/CVE-2022-28738.patch: just free compiled
      pattern if no space is used in regcomp.c, test/ruby/test_regexp.rb.
    - CVE-2022-28738
  * SECURITY UPDATE: Buffer over-read
    - debian/patches/CVE-2022-28739.patch: fix dtoa buffer
      overrun in missing/dtoa.c, test/ruby/test_float.rb.
    - CVE-2022-28739

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 24 May 2022 16:36:26 -0300

CVE-2022-28738 A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untruste
CVE-2022-28739 RESERVED



About   -   Send Feedback to @ubuntu_updates