UbuntuUpdates.org

Package "ruby-rubygems"

Name: ruby-rubygems

Description:

Package management framework for Ruby

Latest version: 3.3.5-2ubuntu1.1
Release: jammy (22.04)
Level: updates
Repository: main
Head package: rubygems
Homepage: https://rubygems.org

Links


Download "ruby-rubygems"


Other versions of "ruby-rubygems" in Jammy

Repository Area Version
base main 3.3.5-2
security main 3.3.5-2ubuntu1.1

Changelog

Version: 3.3.5-2ubuntu1.1 2025-09-04 11:06:59 UTC

  rubygems (3.3.5-2ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: ReDoS
    - debian/patches/CVE-2023-28755.patch: URI.parse should set empty
      string in host instead of nil in lib/uri/rfc3986_parser.rb, raise
      ArgumentError with empty host url again in
      lib/net/http/generic_request.rb.
    - CVE-2023-28755

 -- Nishit Majithia <email address hidden> Tue, 02 Sep 2025 18:04:56 +0530

CVE-2023-28755 A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific cha



About   -   Send Feedback to @ubuntu_updates