[USN-6219-1] Ruby vulnerabilities

Severity Medium
Affected Packages 25
CVEs 2

Several security issues were fixed in Ruby.

It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 20.10 and Ubuntu 20.04 LTS.
(CVE-2023-28755)

It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
This issue exists because of an incomplete fix for CVE-2023-28755.
(CVE-2023-36617)

Package Affected Version
pkg:deb/ubuntu/ruby3.1?distro=lunar < 3.1.2-6ubuntu0.23.04.2
pkg:deb/ubuntu/ruby3.1-doc?distro=lunar < 3.1.2-6ubuntu0.23.04.2
pkg:deb/ubuntu/ruby3.1-dev?distro=lunar < 3.1.2-6ubuntu0.23.04.2
pkg:deb/ubuntu/ruby3.0?distro=kinetic < 3.0.4-7ubuntu0.2
pkg:deb/ubuntu/ruby3.0?distro=jammy < 3.0.2-7ubuntu2.4
pkg:deb/ubuntu/ruby3.0-doc?distro=kinetic < 3.0.4-7ubuntu0.2
pkg:deb/ubuntu/ruby3.0-doc?distro=jammy < 3.0.2-7ubuntu2.4
pkg:deb/ubuntu/ruby3.0-dev?distro=kinetic < 3.0.4-7ubuntu0.2
pkg:deb/ubuntu/ruby3.0-dev?distro=jammy < 3.0.2-7ubuntu2.4
pkg:deb/ubuntu/ruby2.7?distro=focal < 2.7.0-5ubuntu1.12
pkg:deb/ubuntu/ruby2.7-doc?distro=focal < 2.7.0-5ubuntu1.12
pkg:deb/ubuntu/ruby2.7-dev?distro=focal < 2.7.0-5ubuntu1.12
pkg:deb/ubuntu/ruby2.5?distro=bionic < 2.5.1-1ubuntu1.16+esm1
pkg:deb/ubuntu/ruby2.5-doc?distro=bionic < 2.5.1-1ubuntu1.16+esm1
pkg:deb/ubuntu/ruby2.5-dev?distro=bionic < 2.5.1-1ubuntu1.16+esm1
pkg:deb/ubuntu/ruby2.3?distro=xenial < 2.3.1-2~ubuntu16.04.16+esm8
pkg:deb/ubuntu/ruby2.3-tcltk?distro=xenial < 2.3.1-2~ubuntu16.04.16+esm8
pkg:deb/ubuntu/ruby2.3-doc?distro=xenial < 2.3.1-2~ubuntu16.04.16+esm8
pkg:deb/ubuntu/ruby2.3-dev?distro=xenial < 2.3.1-2~ubuntu16.04.16+esm8
pkg:deb/ubuntu/libruby3.1?distro=lunar < 3.1.2-6ubuntu0.23.04.2
pkg:deb/ubuntu/libruby3.0?distro=kinetic < 3.0.4-7ubuntu0.2
pkg:deb/ubuntu/libruby3.0?distro=jammy < 3.0.2-7ubuntu2.4
pkg:deb/ubuntu/libruby2.7?distro=focal < 2.7.0-5ubuntu1.12
pkg:deb/ubuntu/libruby2.5?distro=bionic < 2.5.1-1ubuntu1.16+esm1
pkg:deb/ubuntu/libruby2.3?distro=xenial < 2.3.1-2~ubuntu16.04.16+esm8
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/ruby3.1?distro=lunar ubuntu ruby3.1 < 3.1.2-6ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/ruby3.1-doc?distro=lunar ubuntu ruby3.1-doc < 3.1.2-6ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/ruby3.1-dev?distro=lunar ubuntu ruby3.1-dev < 3.1.2-6ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/ruby3.0?distro=kinetic ubuntu ruby3.0 < 3.0.4-7ubuntu0.2 kinetic
Affected pkg:deb/ubuntu/ruby3.0?distro=jammy ubuntu ruby3.0 < 3.0.2-7ubuntu2.4 jammy
Affected pkg:deb/ubuntu/ruby3.0-doc?distro=kinetic ubuntu ruby3.0-doc < 3.0.4-7ubuntu0.2 kinetic
Affected pkg:deb/ubuntu/ruby3.0-doc?distro=jammy ubuntu ruby3.0-doc < 3.0.2-7ubuntu2.4 jammy
Affected pkg:deb/ubuntu/ruby3.0-dev?distro=kinetic ubuntu ruby3.0-dev < 3.0.4-7ubuntu0.2 kinetic
Affected pkg:deb/ubuntu/ruby3.0-dev?distro=jammy ubuntu ruby3.0-dev < 3.0.2-7ubuntu2.4 jammy
Affected pkg:deb/ubuntu/ruby2.7?distro=focal ubuntu ruby2.7 < 2.7.0-5ubuntu1.12 focal
Affected pkg:deb/ubuntu/ruby2.7-doc?distro=focal ubuntu ruby2.7-doc < 2.7.0-5ubuntu1.12 focal
Affected pkg:deb/ubuntu/ruby2.7-dev?distro=focal ubuntu ruby2.7-dev < 2.7.0-5ubuntu1.12 focal
Affected pkg:deb/ubuntu/ruby2.5?distro=bionic ubuntu ruby2.5 < 2.5.1-1ubuntu1.16+esm1 bionic
Affected pkg:deb/ubuntu/ruby2.5-doc?distro=bionic ubuntu ruby2.5-doc < 2.5.1-1ubuntu1.16+esm1 bionic
Affected pkg:deb/ubuntu/ruby2.5-dev?distro=bionic ubuntu ruby2.5-dev < 2.5.1-1ubuntu1.16+esm1 bionic
Affected pkg:deb/ubuntu/ruby2.3?distro=xenial ubuntu ruby2.3 < 2.3.1-2~ubuntu16.04.16+esm8 xenial
Affected pkg:deb/ubuntu/ruby2.3-tcltk?distro=xenial ubuntu ruby2.3-tcltk < 2.3.1-2~ubuntu16.04.16+esm8 xenial
Affected pkg:deb/ubuntu/ruby2.3-doc?distro=xenial ubuntu ruby2.3-doc < 2.3.1-2~ubuntu16.04.16+esm8 xenial
Affected pkg:deb/ubuntu/ruby2.3-dev?distro=xenial ubuntu ruby2.3-dev < 2.3.1-2~ubuntu16.04.16+esm8 xenial
Affected pkg:deb/ubuntu/libruby3.1?distro=lunar ubuntu libruby3.1 < 3.1.2-6ubuntu0.23.04.2 lunar
Affected pkg:deb/ubuntu/libruby3.0?distro=kinetic ubuntu libruby3.0 < 3.0.4-7ubuntu0.2 kinetic
Affected pkg:deb/ubuntu/libruby3.0?distro=jammy ubuntu libruby3.0 < 3.0.2-7ubuntu2.4 jammy
Affected pkg:deb/ubuntu/libruby2.7?distro=focal ubuntu libruby2.7 < 2.7.0-5ubuntu1.12 focal
Affected pkg:deb/ubuntu/libruby2.5?distro=bionic ubuntu libruby2.5 < 2.5.1-1ubuntu1.16+esm1 bionic
Affected pkg:deb/ubuntu/libruby2.3?distro=xenial ubuntu libruby2.3 < 2.3.1-2~ubuntu16.04.16+esm8 xenial
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...