Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits: 1ff0886c by Salvatore Bonaccorso at 2022-04-22T14:15:23+02:00 Add fixed version for ruby3.0 issues via unstable - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -2092,7 +2092,7 @@ CVE-2022-28740 RESERVED CVE-2022-28739 [Buffer overrun in String-to-Float conversion] RESERVED - - ruby3.0 <unfixed> (bug #1009956) + - ruby3.0 3.0.4-1 (bug #1009956) - ruby2.7 <unfixed> (bug #1009957) [bullseye] - ruby2.7 <postponed> (Minor issue, fix with next Ruby security release) - ruby2.5 <removed> @@ -2105,7 +2105,7 @@ CVE-2022-28739 [Buffer overrun in String-to-Float conversion] NOTE: https://www.ruby-lang.org/en/news/2022/04/12/buffer-overrun-in-string-to-float-cve-2022-28739/ CVE-2022-28738 [Double free in Regexp compilation] RESERVED - - ruby3.0 <unfixed> (bug #1009958) + - ruby3.0 3.0.4-1 (bug #1009958) - ruby2.7 <not-affected> (Vulnerable code not present) - ruby2.5 <not-affected> (Vulnerable code not present) - ruby2.3 <not-affected> (Vulnerable code not present) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1ff0886c0645d7621aa99ea8d97bd91991dcf625 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1ff0886c0645d7621aa99ea8d97bd91991dcf625 You're receiving this email because of your account on salsa.debian.org.
_______________________________________________ debian-security-tracker-commits mailing list debian-security-tracker-commits@alioth-lists.debian.net https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits