UbuntuUpdates.org

Package "ruby3.2"

Name: ruby3.2

Description:

Interpreter of object-oriented scripting language Ruby

Latest version: 3.2.3-1ubuntu0.24.04.1
Release: noble (24.04)
Level: security
Repository: main
Homepage: https://www.ruby-lang.org/

Links


Download "ruby3.2"


Other versions of "ruby3.2" in Noble

Repository Area Version
updates main 3.2.3-1ubuntu0.24.04.1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.2.3-1ubuntu0.24.04.1 2024-06-17 15:07:14 UTC

  ruby3.2 (3.2.3-1ubuntu0.24.04.1) noble-security; urgency=medium

  * SECURITY UPDATE: code execution in RDoc
    - debian/patches/CVE-2024-27281-1.patch: filter marshalled objects in
      lib/rdoc/store.rb.
    - debian/patches/CVE-2024-27281-2.patch: fix NoMethodError for
      start_with in lib/rdoc/store.rb.
    - CVE-2024-27281
  * SECURITY UPDATE: heap data extraction via regex
    - debian/patches/CVE-2024-27282.patch: fix Use-After-Free issue for
      Regexp in regexec.c.
    - CVE-2024-27282

 -- Marc Deslauriers <email address hidden> Fri, 14 Jun 2024 07:50:43 -0400

CVE-2024-27281 An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in Ruby 3.x through 3.3.0. When parsing .rdoc_options (used for configuration in
CVE-2024-27282 An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplied data is provided to the Ruby regex compiler, it is possible to extract arbitr



About   -   Send Feedback to @ubuntu_updates