First published: Wed Jul 12 2023(Updated: )
It was discovered that Ruby incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause a denial of service. This issue only affected Ubuntu 20.10 and Ubuntu 20.04 LTS. (CVE-2023-28755) It was discovered that Ruby incorrectly handled certain regular expressions. An attacker could possibly use this issue to cause a denial of service. This issue exists because of an incomplete fix for CVE-2023-28755. (CVE-2023-36617)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/ruby3.1 | <3.1.2-6ubuntu0.23.04.2 | 3.1.2-6ubuntu0.23.04.2 |
=23.04 | ||
All of | ||
ubuntu/libruby3.1 | <3.1.2-6ubuntu0.23.04.2 | 3.1.2-6ubuntu0.23.04.2 |
=23.04 | ||
All of | ||
ubuntu/ruby3.0 | <3.0.4-7ubuntu0.2 | 3.0.4-7ubuntu0.2 |
=22.10 | ||
All of | ||
ubuntu/libruby3.0 | <3.0.4-7ubuntu0.2 | 3.0.4-7ubuntu0.2 |
=22.10 | ||
All of | ||
ubuntu/ruby3.0 | <3.0.2-7ubuntu2.4 | 3.0.2-7ubuntu2.4 |
=22.04 | ||
All of | ||
ubuntu/libruby3.0 | <3.0.2-7ubuntu2.4 | 3.0.2-7ubuntu2.4 |
=22.04 | ||
All of | ||
ubuntu/ruby2.7 | <2.7.0-5ubuntu1.12 | 2.7.0-5ubuntu1.12 |
=20.04 | ||
All of | ||
ubuntu/libruby2.7 | <2.7.0-5ubuntu1.12 | 2.7.0-5ubuntu1.12 |
=20.04 | ||
All of | ||
ubuntu/ruby2.5 | <2.5.1-1ubuntu1.16+esm1 | 2.5.1-1ubuntu1.16+esm1 |
=18.04 | ||
All of | ||
ubuntu/libruby2.5 | <2.5.1-1ubuntu1.16+esm1 | 2.5.1-1ubuntu1.16+esm1 |
=18.04 | ||
All of | ||
ubuntu/libruby2.3 | <2.3.1-2~ubuntu16.04.16+esm8 | 2.3.1-2~ubuntu16.04.16+esm8 |
=16.04 | ||
All of | ||
ubuntu/ruby2.3 | <2.3.1-2~ubuntu16.04.16+esm8 | 2.3.1-2~ubuntu16.04.16+esm8 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-28755 is medium.
To fix the Ruby vulnerabilities in Ubuntu, update to the specified versions: 3.1.2-6ubuntu0.23.04.2 for ruby3.1, 3.1.2-6ubuntu0.23.04.2 for libruby3.1, 3.0.4-7ubuntu0.2 for ruby3.0, 3.0.4-7ubuntu0.2 for libruby3.0, 3.0.2-7ubuntu2.4 for ruby3.0, 3.0.2-7ubuntu2.4 for libruby3.0, 2.7.0-5ubuntu1.12 for ruby2.7, 2.7.0-5ubuntu1.12 for libruby2.7, 2.5.1-1ubuntu1.16+esm1 for ruby2.5, 2.5.1-1ubuntu1.16+esm1 for libruby2.5, 2.3.1-2~ubuntu16.04.16+esm8 for libruby2.3, and 2.3.1-2~ubuntu16.04.16+esm8 for ruby2.3.
The Ruby vulnerabilities affect Ubuntu versions 23.04, 22.10, 22.04, 20.04, 18.04, and 16.04.
The remedy for CVE-2023-28755 is to update to version 3.1.2-6ubuntu0.23.04.2 or later.
You can find more information about the Ruby vulnerabilities in Ubuntu on the Ubuntu Security Notices page.