Information on source package ruby2.5

Available versions

ReleaseVersion
buster2.5.5-3+deb10u7
buster (security)2.5.5-3+deb10u6

Open issues

BugbusterDescription
CVE-2024-43398vulnerable (no DSA, postponed)REXML is an XML toolkit for Ruby. The REXML gem before 3.3.6 has a DoS ...
CVE-2024-41946vulnerable (no DSA, postponed)REXML is an XML toolkit for Ruby. The REXML gem 3.3.2 has a DoS vulner ...
CVE-2024-41123vulnerable (no DSA, postponed)REXML is an XML toolkit for Ruby. The REXML gem before 3.3.2 has some ...
CVE-2024-39908vulnerable (no DSA, postponed)REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has some ...
CVE-2024-35176vulnerable (no DSA, postponed)REXML is an XML toolkit for Ruby. The REXML gem before 3.2.6 has a den ...

Resolved issues

BugDescription
CVE-2024-27282An issue was discovered in Ruby 3.x through 3.3.0. If attacker-supplie ...
CVE-2024-27281An issue was discovered in RDoc 6.3.3 through 6.6.2, as distributed in ...
CVE-2024-27280A buffer-overread issue was discovered in StringIO 3.0.1, as distribut ...
CVE-2023-36617A ReDoS issue was discovered in the URI component before 0.12.2 for Ru ...
CVE-2023-28756A ReDoS issue was discovered in the Time component through 0.2.1 in Ru ...
CVE-2023-28755A ReDoS issue was discovered in the URI component through 0.12.0 in Ru ...
CVE-2022-28739There is a buffer over-read in Ruby before 2.6.10, 2.7.x before 2.7.6, ...
CVE-2022-28738A double free was found in the Regexp compiler in Ruby 3.x before 3.0. ...
CVE-2021-41819CGI::Cookie.parse in Ruby through 2.6.8 mishandles security prefixes i ...
CVE-2021-41817Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regula ...
CVE-2021-41816CGI.escape_html in Ruby before 2.7.5 and 3.x before 3.0.3 has an integ ...
CVE-2021-33621The cgi gem before 0.1.0.2, 0.2.x before 0.2.2, and 0.3.x before 0.3.5 ...
CVE-2021-32066An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, an ...
CVE-2021-31810An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, an ...
CVE-2021-31799In RDoc 3.11 through 6.x before 6.3.1, as distributed with Ruby throug ...
CVE-2021-28965The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, a ...
CVE-2020-25613An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, an ...
CVE-2020-10933An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6 ...
CVE-2020-10663The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9 ...
CVE-2019-16255Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allow ...
CVE-2019-16254Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allow ...
CVE-2019-16201WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5 ...
CVE-2019-15845Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 misha ...
CVE-2019-8325An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since ...
CVE-2019-8324An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...
CVE-2019-8323An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem:: ...
CVE-2019-8322An issue was discovered in RubyGems 2.6 and later through 3.0.2. The g ...
CVE-2019-8321An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since ...
CVE-2019-8320A Directory Traversal issue was discovered in RubyGems 2.7.6 and later ...
CVE-2018-1000079RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000078RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000077RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000076RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000075RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000074RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000073RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-16396An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5. ...
CVE-2018-16395An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2 ...
CVE-2018-8780In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x b ...
CVE-2018-8779In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x b ...
CVE-2018-8778In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x b ...
CVE-2018-8777In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x b ...
CVE-2018-6914Directory traversal vulnerability in the Dir.mktmpdir method in the tm ...
CVE-2017-17790The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 us ...
CVE-2017-17742Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x befo ...
CVE-2017-17405Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, get ...

Security announcements

DSA / DLADescription
ELA-1150-1ruby2.5 - security update
DLA-3450-1ruby2.5 - security update
DLA-3447-1ruby2.5 - security update
DSA-5066-1ruby2.5 - security update
DSA-4721-1ruby2.5 - security update
DSA-4586-1ruby2.5 - security update

Search for package or bug name: Reporting problems