FlawAtlas
Search the atlas
SUSE-SU-2022:1512-1 Not scored

Security update for ruby2.5

This update for ruby2.5 fixes the following issues: - CVE-2022-28739: Fixed a buffer overrun in String-to-Float conversion (bsc#1198441). - CVE-2021-41817: Fixed a regular expression denial of service in Date Parsing Methods (bsc#1193035). - CVE-2021-32066: Fixed a StartTLS stripping vulnerability in Net:IMAP (bsc#1188160). - CVE-2021-31810: Fixed a trusting FTP PASV responses vulnerability in Net:FTP (bsc#1188161). - CVE-2021-31799: Fixed a command injection vulnerability in RDoc (bsc#1190375).

Exploit probability Not scored
Published May 3, 2022
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 6 ruby2.5
SUSE:Enterprise Storage 7 ruby2.5
SUSE:Linux Enterprise High Performance Computing 15 SP1-ESPOS ruby2.5
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS ruby2.5
SUSE:Linux Enterprise High Performance Computing 15 SP2-ESPOS ruby2.5
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS ruby2.5
SUSE:Linux Enterprise High Performance Computing 15-ESPOS ruby2.5
SUSE:Linux Enterprise High Performance Computing 15-LTSS ruby2.5
SUSE:Linux Enterprise Micro 5.0 ruby2.5
SUSE:Linux Enterprise Module for Basesystem 15 SP3 ruby2.5
SUSE:Linux Enterprise Real Time 15 SP2 ruby2.5
SUSE:Linux Enterprise Server 15 SP1-BCL ruby2.5
SUSE:Linux Enterprise Server 15 SP1-LTSS ruby2.5
SUSE:Linux Enterprise Server 15 SP2-BCL ruby2.5
SUSE:Linux Enterprise Server 15 SP2-LTSS ruby2.5
SUSE:Linux Enterprise Server 15-LTSS ruby2.5
SUSE:Linux Enterprise Server for SAP Applications 15 ruby2.5
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 ruby2.5
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 ruby2.5
SUSE:Manager Proxy 4.1 ruby2.5
SUSE:Manager Retail Branch Server 4.1 ruby2.5
SUSE:Manager Server 4.1 ruby2.5
openSUSE:Leap 15.3 ruby2.5
openSUSE:Leap 15.4 ruby2.5

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2022:1512-1

This update for ruby2.5 fixes the following issues: - CVE-2022-28739: Fixed a buffer overrun in String-to-Float conversion (bsc#1198441). - CVE-2021-41817: Fixed a regular expression denial of service in Date Parsing Methods (bsc#1193035). - CVE-2021-32066: Fixed a StartTLS stripping vulnerability in Net:IMAP (bsc#1188160). - CVE-2021-31810: Fixed a trusting FTP PASV responses vulnerability in Net:FTP (bsc#1188161). - CVE-2021-31799: Fixed a command injection vulnerability in RDoc (bsc#1190375).

View original source

05 / REFERENCES

Further evidence