Описание
Security update for ruby2.5
This update for ruby2.5 fixes the following issues:
- Update to 2.5.9
- CVE-2021-28965: XML round-trip vulnerability in REXML (bsc#1184644)
This update was imported from the SUSE:SLE-15:Update update project.
Список пакетов
openSUSE Leap 15.2
libruby2_5-2_5-2.5.9-lp152.2.6.1
ruby2.5-2.5.9-lp152.2.6.1
ruby2.5-devel-2.5.9-lp152.2.6.1
ruby2.5-devel-extra-2.5.9-lp152.2.6.1
ruby2.5-doc-2.5.9-lp152.2.6.1
ruby2.5-doc-ri-2.5.9-lp152.2.6.1
ruby2.5-stdlib-2.5.9-lp152.2.6.1
Ссылки
- E-Mail link for openSUSE-SU-2021:0607-1
- SUSE Security Ratings
- SUSE Bug 1184644
- SUSE CVE CVE-2021-28965 page
Описание
The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorrect document can be produced after parsing and serializing.
Затронутые продукты
openSUSE Leap 15.2:libruby2_5-2_5-2.5.9-lp152.2.6.1
openSUSE Leap 15.2:ruby2.5-2.5.9-lp152.2.6.1
openSUSE Leap 15.2:ruby2.5-devel-2.5.9-lp152.2.6.1
openSUSE Leap 15.2:ruby2.5-devel-extra-2.5.9-lp152.2.6.1
Ссылки
- CVE-2021-28965
- SUSE Bug 1184644