Lucene search

K
ubuntuUbuntuUSN-6055-2
HistoryMay 05, 2023 - 12:00 a.m.

Ruby regression

2023-05-0500:00:00
ubuntu.com
48
ubuntu
ruby
vulnerability

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

6.1

Confidence

High

EPSS

0.004

Percentile

72.3%

Releases

  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM

Packages

  • ruby2.3 - Object-oriented scripting language
  • ruby2.5 - Object-oriented scripting language
  • ruby2.7 - Object-oriented scripting language

Details

USN-6055-1 fixed a vulnerability in Ruby. Unfortunately it introduced a regression.
This update reverts the patches applied to CVE-2023-28755 in order to fix the regression
pending further investigation.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Ruby incorrectly handled certain regular expressions.
An attacker could possibly use this issue to cause a denial of service.
(CVE-2023-28755)

OSVersionArchitecturePackageVersionFilename
Ubuntu20.04noarchruby2.7< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchlibruby2.7< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchlibruby2.7-dbgsym< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchruby2.7-dbgsym< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchruby2.7-dev< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu20.04noarchruby2.7-doc< 2.7.0-5ubuntu1.10UNKNOWN
Ubuntu18.04noarchruby2.5< 2.5.1-1ubuntu1.15UNKNOWN
Ubuntu18.04noarchlibruby2.5< 2.5.1-1ubuntu1.15UNKNOWN
Ubuntu18.04noarchlibruby2.5-dbgsym< 2.5.1-1ubuntu1.15UNKNOWN
Ubuntu18.04noarchruby2.5-dbgsym< 2.5.1-1ubuntu1.15UNKNOWN
Rows per page:
1-10 of 241

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

AI Score

6.1

Confidence

High

EPSS

0.004

Percentile

72.3%