UBUNTU-CVE-2022-28739
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-28739
UBUNTU-CVE-2022-28739
Summary:
Details: There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, 3.x before 3.0.4, and 3.1.x before 3.1.2. It occurs in String-to-Float conversion, including Kernel#Float and String#to_f.
References: https://ubuntu.com/security/CVE-2022-28739, https://github.com/ruby/ruby/commit/69f9992ed41920389d4185141a14f02f89a4d306, https://github.com/ruby/ruby/commit/c9c2245c0a25176072e02db9254f0e0c84c805cd, https://github.com/ruby/ruby/commit/3fa771ddedac25560be57f4055f1767e6c810f58, https://github.com/ruby/ruby/commit/8d142ecff9af7d60728b8cfa9138e8623985c428, https://www.ruby-lang.org/en/news/2022/04/12/buffer-overrun-in-string-to-float-cve-2022-28739/, https://access.redhat.com/security/cve/CVE-2022-28739, https://ubuntu.com/security/notices/USN-5462-2, https://ubuntu.com/security/notices/USN-5462-1, https://www.cve.org/CVERecord?id=CVE-2022-28739
Affected packages
Package
Name: ruby2.3
Purl: pkg:deb/ubuntu/[email protected]~ubuntu16.04.16+esm3?arch=source&distro=esm-infra/xenial
Affected ranges
Type: ECOSYSTEM
Events:
