[USN-5462-1] Ruby vulnerabilities

Severity Medium
Affected Packages 16
CVEs 2

Several security issues were fixed in Ruby.

It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to execute arbitrary code. This
issue only affected Ubuntu 22.04 LTS. (CVE-2022-28738)

It was discovered that Ruby incorrectly handled certain inputs.
An attacker could possibly use this issue to expose sensitive information.
(CVE-2022-28739)

Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/ruby3.0?distro=jammy ubuntu ruby3.0 < 3.0.2-7ubuntu2.1 jammy
Affected pkg:deb/ubuntu/ruby3.0-doc?distro=jammy ubuntu ruby3.0-doc < 3.0.2-7ubuntu2.1 jammy
Affected pkg:deb/ubuntu/ruby3.0-dev?distro=jammy ubuntu ruby3.0-dev < 3.0.2-7ubuntu2.1 jammy
Affected pkg:deb/ubuntu/ruby2.7?distro=impish ubuntu ruby2.7 < 2.7.4-1ubuntu3.2 impish
Affected pkg:deb/ubuntu/ruby2.7?distro=focal ubuntu ruby2.7 < 2.7.0-5ubuntu1.7 focal
Affected pkg:deb/ubuntu/ruby2.7-doc?distro=impish ubuntu ruby2.7-doc < 2.7.4-1ubuntu3.2 impish
Affected pkg:deb/ubuntu/ruby2.7-doc?distro=focal ubuntu ruby2.7-doc < 2.7.0-5ubuntu1.7 focal
Affected pkg:deb/ubuntu/ruby2.7-dev?distro=impish ubuntu ruby2.7-dev < 2.7.4-1ubuntu3.2 impish
Affected pkg:deb/ubuntu/ruby2.7-dev?distro=focal ubuntu ruby2.7-dev < 2.7.0-5ubuntu1.7 focal
Affected pkg:deb/ubuntu/ruby2.5?distro=bionic ubuntu ruby2.5 < 2.5.1-1ubuntu1.12 bionic
Affected pkg:deb/ubuntu/ruby2.5-doc?distro=bionic ubuntu ruby2.5-doc < 2.5.1-1ubuntu1.12 bionic
Affected pkg:deb/ubuntu/ruby2.5-dev?distro=bionic ubuntu ruby2.5-dev < 2.5.1-1ubuntu1.12 bionic
Affected pkg:deb/ubuntu/libruby3.0?distro=jammy ubuntu libruby3.0 < 3.0.2-7ubuntu2.1 jammy
Affected pkg:deb/ubuntu/libruby2.7?distro=impish ubuntu libruby2.7 < 2.7.4-1ubuntu3.2 impish
Affected pkg:deb/ubuntu/libruby2.7?distro=focal ubuntu libruby2.7 < 2.7.0-5ubuntu1.7 focal
Affected pkg:deb/ubuntu/libruby2.5?distro=bionic ubuntu libruby2.5 < 2.5.1-1ubuntu1.12 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...