Summary: | <dev-lang/ruby-{2.7.8, 3.0.6, 3.1.4, 3.2.2}: ReDoS vulnerability in Time and URI | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | Hans de Graaff <graaff> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | minor | CC: | ajak, ruby |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B3 [glsa+] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 904759 | ||
Bug Blocks: |
Description
Hans de Graaff
![]() ![]() Fixed in ruby 2.7.8, ruby 3.0.6, ruby 3.1.4 and ruby 3.2.2, and in dev-ruby/time-0.2.2. URI is only shipped bundled with dev-lang/ruby at the moment. Given that upstream likes to mix in other fixes with security updates I'd like to wait a couple of days before filing a stable bug. Cleanup done. (In reply to Hans de Graaff from comment #2) > Cleanup done. Not for 2.7.x? (In reply to John Helmert III from comment #3) > (In reply to Hans de Graaff from comment #2) > > Cleanup done. > > Not for 2.7.x? That version was already masked for removal, IIRC. The bug has been referenced in the following commit(s): https://gitweb.gentoo.org/data/glsa.git/commit/?id=aea6781bb25fe500e38a2cfce23bf166d29cbf48 commit aea6781bb25fe500e38a2cfce23bf166d29cbf48 Author: GLSAMaker <glsamaker@gentoo.org> AuthorDate: 2024-01-24 04:04:06 +0000 Commit: John Helmert III <ajak@gentoo.org> CommitDate: 2024-01-24 04:06:47 +0000 [ GLSA 202401-27 ] Ruby: Multiple vulnerabilities Bug: https://bugs.gentoo.org/747007 Bug: https://bugs.gentoo.org/801061 Bug: https://bugs.gentoo.org/827251 Bug: https://bugs.gentoo.org/838073 Bug: https://bugs.gentoo.org/882893 Bug: https://bugs.gentoo.org/903630 Signed-off-by: GLSAMaker <glsamaker@gentoo.org> Signed-off-by: John Helmert III <ajak@gentoo.org> glsa-202401-27.xml | 65 ++++++++++++++++++++++++++++++++++++++++++++++++++++++ 1 file changed, 65 insertions(+) |