OESA-2022-1700
Dashboard / Vulnerabilities / OESA-2022-1700
OESA-2022-1700
Summary: ruby security update
Details: Ruby is a fast and easy interpreted scripting language for object-oriented programming. It has many functions for processing text Files and perform system management tasks (such as Perl). Security Fix(es): There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.(CVE-2022-28739) A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untrusted user input, an attacker may be able to write to unexpected memory locations.(CVE-2022-28738)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1700, https://nvd.nist.gov/vuln/detail/CVE-2022-28739, https://nvd.nist.gov/vuln/detail/CVE-2022-28738
Affected packages
Package
Name: ruby
Purl: pkg:rpm/openEuler/ruby&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
