Lucene search

K
ubuntuUbuntuUSN-6055-2
HistoryMay 05, 2023 - 12:00 a.m.

Ruby regression

2023-05-0500:00:00
ubuntu.com
34
ubuntu
ruby
vulnerability

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%

Releases

  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • ruby2.3 - Object-oriented scripting language
  • ruby2.5 - Object-oriented scripting language
  • ruby2.7 - Object-oriented scripting language

Details

USN-6055-1 fixed a vulnerability in Ruby. Unfortunately it introduced a regression.
This update reverts the patches applied to CVE-2023-28755 in order to fix the regression
pending further investigation.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755)

OSVersionArchitecturePackageVersionFilename
Ubuntu20.04noarchruby2.7< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchlibruby2.7< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchlibruby2.7-dbgsym< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchruby2.7-dbgsym< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchruby2.7-dev< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchruby2.7-doc< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu18.04noarchruby2.5< 2.5.1-1ubuntu1.15UNKNOWN
Ubuntu18.04noarchlibruby2.5< 2.5.1-1ubuntu1.15UNKNOWN
Ubuntu18.04noarchlibruby2.5-dbgsym< 2.5.1-1ubuntu1.15UNKNOWN
Ubuntu18.04noarchruby2.5-dbgsym< 2.5.1-1ubuntu1.15UNKNOWN
Rows per page:
1-10 of 241

5.3 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

6.1 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

69.5%