Corrective releases of Ruby 3.1.2, 3.0.4, 2.7.6, 2.6.10 addressing vulnerabilities

Corrective releases for the Ruby programming language 3.1.2, 3.0.4, 2.7.6, and 2.6.10 have been issued, addressing two vulnerabilities:

  • CVE-2022-28738 — a double-free vulnerability in the regular expression compilation code that occurs when a specially crafted string is passed during the creation of a Regexp object. The vulnerability can be exploited when unverified external data is used in a Regexp object.
  • CVE-2022-28739 — a buffer overflow in the code that converts a string to a floating-point number. The vulnerability can potentially be exploited to gain access to memory content when processing unverified external data in methods like Kernel#Float and String#to_f.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster