Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1ff0886c by Salvatore Bonaccorso at 2022-04-22T14:15:23+02:00
Add fixed version for ruby3.0 issues via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2092,7 +2092,7 @@ CVE-2022-28740
        RESERVED
 CVE-2022-28739 [Buffer overrun in String-to-Float conversion]
        RESERVED
-       - ruby3.0 <unfixed> (bug #1009956)
+       - ruby3.0 3.0.4-1 (bug #1009956)
        - ruby2.7 <unfixed> (bug #1009957)
        [bullseye] - ruby2.7 <postponed> (Minor issue, fix with next Ruby 
security release)
        - ruby2.5 <removed>
@@ -2105,7 +2105,7 @@ CVE-2022-28739 [Buffer overrun in String-to-Float 
conversion]
        NOTE: 
https://www.ruby-lang.org/en/news/2022/04/12/buffer-overrun-in-string-to-float-cve-2022-28739/
 CVE-2022-28738 [Double free in Regexp compilation]
        RESERVED
-       - ruby3.0 <unfixed> (bug #1009958)
+       - ruby3.0 3.0.4-1 (bug #1009958)
        - ruby2.7 <not-affected> (Vulnerable code not present)
        - ruby2.5 <not-affected> (Vulnerable code not present)
        - ruby2.3 <not-affected> (Vulnerable code not present)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1ff0886c0645d7621aa99ea8d97bd91991dcf625

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1ff0886c0645d7621aa99ea8d97bd91991dcf625
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
debian-security-tracker-commits@alioth-lists.debian.net
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to