USN-6055-2
Dashboard / Vulnerabilities / USN-6055-2
USN-6055-2
Summary: ruby2.3, ruby2.5, ruby2.7 regression
Details: USN-6055-1 fixed a vulnerability in Ruby. Unfortunately it introduced a regression. This update reverts the patches applied to CVE-2023-28755 in order to fix the regression pending further investigation. We apologize for the inconvenience. Original advisory details: It was discovered that Ruby incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause a denial of service. (CVE-2023-28755)
References: https://ubuntu.com/security/notices/USN-6055-2, https://ubuntu.com/security/CVE-2023-28755, https://launchpad.net/bugs/2018547
Affected packages
Package
Name: ruby2.3
Purl: pkg:deb/ubuntu/ruby2.3?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
