UbuntuUpdates.org

Package "ruby3.0"

Name: ruby3.0

Description:

Interpreter of object-oriented scripting language Ruby

Latest version: 3.0.2-7ubuntu2.3
Release: jammy (22.04)
Level: updates
Repository: main
Homepage: https://www.ruby-lang.org/

Links


Download "ruby3.0"


Other versions of "ruby3.0" in Jammy

Repository Area Version
security main 3.0.2-7ubuntu2.3

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.0.2-7ubuntu2.3 2023-01-23 18:07:32 UTC

  ruby3.0 (3.0.2-7ubuntu2.3) jammy-security; urgency=medium

  * SECURITY UPDATE: HTTP response splitting
    - debian/patches/CVE-2021-33621*.patch: adds regex to lib/cgi/core.rb and
      lib/cgi/cookie.rb along with tests to check http response headers and
      cookie fields for invalid characters.
    - debian/patches/fix_tzdata-2022.patch: fix for tzdata-2022g tests
      in test/ruby/test_time_tz.rb.
    - CVE-2021-33621

 -- Leonidas Da Silva Barbosa <email address hidden> Wed, 18 Jan 2023 14:28:21 -0300

Source diff to previous version
CVE-2021-33621 The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 for Ruby allows HTTP response splitting. This is relevant to applications that

Version: 3.0.2-7ubuntu2.2 2022-12-01 12:07:22 UTC

  ruby3.0 (3.0.2-7ubuntu2.2) jammy; urgency=medium

  * d/p/fix-length-calc-for-Array#slice.patch: Add patch to
    fix length calculation for Array#slice!. (LP: #1982703)

 -- Utkarsh Gupta <email address hidden> Mon, 14 Nov 2022 17:21:06 +0530

Source diff to previous version
1982703 Segfaults in ruby 3.0.2

Version: 3.0.2-7ubuntu2.1 2022-06-06 22:06:20 UTC

  ruby3.0 (3.0.2-7ubuntu2.1) jammy-security; urgency=medium

  * SECURITY UPDATE: Double free
    - debian/patches/CVE-2022-28738.patch: just free compiled
      pattern if no space is used in regcomp.c, test/ruby/test_regexp.rb.
    - CVE-2022-28738
  * SECURITY UPDATE: Buffer over-read
    - debian/patches/CVE-2022-28739.patch: fix dtoa buffer
      overrun in missing/dtoa.c, test/ruby/test_float.rb.
    - CVE-2022-28739

 -- Leonidas Da Silva Barbosa <email address hidden> Tue, 24 May 2022 16:36:26 -0300

CVE-2022-28738 A double free was found in the Regexp compiler in Ruby 3.x before 3.0.4 and 3.1.x before 3.1.2. If a victim attempts to create a Regexp from untruste
CVE-2022-28739 RESERVED



About   -   Send Feedback to @ubuntu_updates