UbuntuUpdates.org

Package "rubygems"

Name: rubygems

Description:

This package is just an umbrella for a group of other packages, it has no description.
Description samples from packages in group:

  • Package management framework for Ruby

Latest version: 3.3.5-2ubuntu1.1
Release: jammy (22.04)
Level: updates
Repository: main

Links



Other versions of "rubygems" in Jammy

Repository Area Version
base main 3.3.5-2
base universe 2.3.5-2
security main 3.3.5-2ubuntu1.1
security universe 2.3.5-2ubuntu1.1
updates universe 2.3.5-2ubuntu1.1
proposed main 3.3.5-2ubuntu1
proposed universe 2.3.5-2ubuntu1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 3.3.5-2ubuntu1.1 2025-09-04 11:06:59 UTC

  rubygems (3.3.5-2ubuntu1.1) jammy-security; urgency=medium

  * SECURITY UPDATE: ReDoS
    - debian/patches/CVE-2023-28755.patch: URI.parse should set empty
      string in host instead of nil in lib/uri/rfc3986_parser.rb, raise
      ArgumentError with empty host url again in
      lib/net/http/generic_request.rb.
    - CVE-2023-28755

 -- Nishit Majithia <email address hidden> Tue, 02 Sep 2025 18:04:56 +0530

CVE-2023-28755 A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific cha



About   -   Send Feedback to @ubuntu_updates