Security update for ruby2.5
This update for ruby2.5 fixes the following issues: - CVE-2023-28755: Fixed a ReDoS vulnerability in URI. (bsc#1209891) - CVE-2023-28756: Fixed an expensive regexp in the RFC2822 time parser. (bsc#1209967) - CVE-2021-41817: Fixed a Regular Expression Denial of Service Vulnerability of Date Parsing Methods. (bsc#1193035) - CVE-2021-33621: Fixed a HTTP response splitting vulnerability in CGI gem. (bsc#1205726)
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for ruby2.5 fixes the following issues: - CVE-2023-28755: Fixed a ReDoS vulnerability in URI. (bsc#1209891) - CVE-2023-28756: Fixed an expensive regexp in the RFC2822 time parser. (bsc#1209967) - CVE-2021-41817: Fixed a Regular Expression Denial of Service Vulnerability of Date Parsing Methods. (bsc#1193035) - CVE-2021-33621: Fixed a HTTP response splitting vulnerability in CGI gem. (bsc#1205726)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1193035
- https://bugzilla.suse.com/1205726
- https://bugzilla.suse.com/1209891
- https://bugzilla.suse.com/1209967
- https://www.suse.com/security/cve/CVE-2021-33621
- https://www.suse.com/security/cve/CVE-2021-41817
- https://www.suse.com/security/cve/CVE-2023-28755
- https://www.suse.com/security/cve/CVE-2023-28756
- https://www.suse.com/support/update/announcement/2023/suse-su-20234176-1/