SUSE-SU-2025:1369-1
Not scored
Security update for ruby2.5
This update for ruby2.5 fixes the following issues: - CVE-2025-27219: Fixed denial of service in CGI::Cookie.parse (bsc#1237804) - CVE-2025-27220: Fixed ReDoS in CGI::Util#escapeElement (bsc#1237806) Other fixes: - Improved fix for CVE-2024-47220 (bsc#1230930, bsc#1235773)
Exploit probability
Not scored
Published
April 24, 2025
Required by
Not available
Last source change
February 4, 2026
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Open Source Vulnerabilities
SUSE-SU-2025:1369-1
View original source
This update for ruby2.5 fixes the following issues: - CVE-2025-27219: Fixed denial of service in CGI::Cookie.parse (bsc#1237804) - CVE-2025-27220: Fixed ReDoS in CGI::Util#escapeElement (bsc#1237806) Other fixes: - Improved fix for CVE-2024-47220 (bsc#1230930, bsc#1235773)
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1230930
- https://bugzilla.suse.com/1235773
- https://bugzilla.suse.com/1237804
- https://bugzilla.suse.com/1237806
- https://www.suse.com/security/cve/CVE-2024-47220
- https://www.suse.com/security/cve/CVE-2025-27219
- https://www.suse.com/security/cve/CVE-2025-27220
- https://www.suse.com/support/update/announcement/2025/suse-su-20251369-1/