Navigation Menu

Skip to content
This repository has been archived by the owner on Oct 10, 2023. It is now read-only.

0.366.0

Compare
Choose a tag to compare
@cf-buildpacks-eng cf-buildpacks-eng released this 18 May 14:00
· 3 commits to main since this release

Notably, this release addresses:

USN-6087-1 USN-6087-1: Ruby vulnerabilities:

  • CVE-2023-28755: A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
  • CVE-2023-28756: A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
  • CVE-2023-28756: A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to Time objects. The fixed versions are 0.1.1 and 0.2.2.
  • CVE-2023-28755: A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects. The fixed versions are 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1.
-ii  libruby2.5:amd64 2.5.1-1ubuntu1.15  amd64  Libraries necessary to run Ruby 2.5
+ii  libruby2.5:amd64 2.5.1-1ubuntu1.16  amd64  Libraries necessary to run Ruby 2.5
-ii  ruby2.5          2.5.1-1ubuntu1.15  amd64  Interpreter of object-oriented scripting language Ruby
+ii  ruby2.5          2.5.1-1ubuntu1.16  amd64  Interpreter of object-oriented scripting language Ruby