FlawAtlas
Search the atlas
SUSE-SU-2023:4176-1 Not scored

Security update for ruby2.5

This update for ruby2.5 fixes the following issues: - CVE-2023-28755: Fixed a ReDoS vulnerability in URI. (bsc#1209891) - CVE-2023-28756: Fixed an expensive regexp in the RFC2822 time parser. (bsc#1209967) - CVE-2021-41817: Fixed a Regular Expression Denial of Service Vulnerability of Date Parsing Methods. (bsc#1193035) - CVE-2021-33621: Fixed a HTTP response splitting vulnerability in CGI gem. (bsc#1205726)

Exploit probability Not scored
Published October 24, 2023
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 7.1 ruby2.5
SUSE:Linux Enterprise High Performance Computing 15 SP1-LTSS ruby2.5
SUSE:Linux Enterprise High Performance Computing 15 SP2-LTSS ruby2.5
SUSE:Linux Enterprise High Performance Computing 15 SP3-ESPOS ruby2.5
SUSE:Linux Enterprise High Performance Computing 15 SP3-LTSS ruby2.5
SUSE:Linux Enterprise Module for Basesystem 15 SP4 ruby2.5
SUSE:Linux Enterprise Module for Basesystem 15 SP5 ruby2.5
SUSE:Linux Enterprise Server 15 SP1-LTSS ruby2.5
SUSE:Linux Enterprise Server 15 SP2-LTSS ruby2.5
SUSE:Linux Enterprise Server 15 SP3-LTSS ruby2.5
SUSE:Linux Enterprise Server for SAP Applications 15 SP1 ruby2.5
SUSE:Linux Enterprise Server for SAP Applications 15 SP2 ruby2.5
SUSE:Linux Enterprise Server for SAP Applications 15 SP3 ruby2.5
SUSE:Manager Proxy 4.2 ruby2.5
SUSE:Manager Server 4.2 ruby2.5
openSUSE:Leap 15.4 ruby2.5
openSUSE:Leap 15.5 ruby2.5

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2023:4176-1

This update for ruby2.5 fixes the following issues: - CVE-2023-28755: Fixed a ReDoS vulnerability in URI. (bsc#1209891) - CVE-2023-28756: Fixed an expensive regexp in the RFC2822 time parser. (bsc#1209967) - CVE-2021-41817: Fixed a Regular Expression Denial of Service Vulnerability of Date Parsing Methods. (bsc#1193035) - CVE-2021-33621: Fixed a HTTP response splitting vulnerability in CGI gem. (bsc#1205726)

View original source

05 / REFERENCES

Further evidence