Information on source package ruby2.3

Available versions

ReleaseVersion
stretch2.3.3-1+deb9u8
stretch (security)2.3.3-1+deb9u7

Resolved issues

BugDescription
CVE-2020-10933An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6 ...
CVE-2020-10663The JSON gem through 2.2.0 for Ruby, as used in Ruby 2.4 through 2.4.9 ...
CVE-2019-8325An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since ...
CVE-2019-8324An issue was discovered in RubyGems 2.6 and later through 3.0.2. A cra ...
CVE-2019-8323An issue was discovered in RubyGems 2.6 and later through 3.0.2. Gem:: ...
CVE-2019-8322An issue was discovered in RubyGems 2.6 and later through 3.0.2. The g ...
CVE-2019-8321An issue was discovered in RubyGems 2.6 and later through 3.0.2. Since ...
CVE-2019-8320A Directory Traversal issue was discovered in RubyGems 2.7.6 and later ...
CVE-2019-16255Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allow ...
CVE-2019-16254Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allow ...
CVE-2019-16201WEBrick::HTTPAuth::DigestAuth in Ruby through 2.4.7, 2.5.x through 2.5 ...
CVE-2019-15845Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 misha ...
CVE-2018-8780In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x b ...
CVE-2018-8779In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x b ...
CVE-2018-8778In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x b ...
CVE-2018-8777In Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x b ...
CVE-2018-6914Directory traversal vulnerability in the Dir.mktmpdir method in the tm ...
CVE-2018-16396An issue was discovered in Ruby before 2.3.8, 2.4.x before 2.4.5, 2.5. ...
CVE-2018-16395An issue was discovered in the OpenSSL library in Ruby before 2.3.8, 2 ...
CVE-2018-1000079RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000078RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000077RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000076RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000075RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000074RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2018-1000073RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...
CVE-2017-6181The parse_char_class function in regparse.c in the Onigmo (aka Oniguru ...
CVE-2017-17790The lazy_initialize function in lib/resolv.rb in Ruby through 2.4.3 us ...
CVE-2017-17742Ruby before 2.2.10, 2.3.x before 2.3.7, 2.4.x before 2.4.4, 2.5.x befo ...
CVE-2017-17405Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, get ...
CVE-2017-14064Ruby through 2.2.7, 2.3.x through 2.3.4, and 2.4.x through 2.4.1 can e ...
CVE-2017-14033The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2. ...
CVE-2017-11465The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows a ...
CVE-2017-10784The Basic authentication code in WEBrick library in Ruby before 2.2.8, ...
CVE-2017-0903RubyGems versions between 2.0.0 and 2.6.13 are vulnerable to a possibl ...
CVE-2017-0902RubyGems version 2.6.12 and earlier is vulnerable to a DNS hijacking v ...
CVE-2017-0901RubyGems version 2.6.12 and earlier fails to validate specification na ...
CVE-2017-0900RubyGems version 2.6.12 and earlier is vulnerable to maliciously craft ...
CVE-2017-0899RubyGems version 2.6.12 and earlier is vulnerable to maliciously craft ...
CVE-2017-0898Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious forma ...
CVE-2016-7798The openssl gem for Ruby uses the same initialization vector (IV) in G ...
CVE-2016-2339An exploitable heap overflow vulnerability exists in the Fiddle::Funct ...
CVE-2016-2338An exploitable heap overflow vulnerability exists in the Psych::Emitte ...
CVE-2016-2337Type confusion exists in _cancel_eval Ruby's TclTkIp class method. Att ...
CVE-2016-2336Type confusion exists in two methods of Ruby's WIN32OLE class, ole_inv ...
CVE-2015-9096Net::SMTP in Ruby before 2.4.0 is vulnerable to SMTP command injection ...

Security announcements

DSA / DLADescription
DSA-4587-1ruby2.3 - security update
DSA-4433-1ruby2.3 - security update
DSA-4332-1ruby2.3 - security update
DSA-4259-1ruby2.3 - security update
DSA-4031-1ruby2.3 - security update
DSA-3966-1ruby2.3 - security update

Search for package or bug name: Reporting problems