ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ Ruby 3.1.2, 3.0.4, 2.7.6, 2.6.10 ืขื ืคื’ื™ืขื•ื™ื•ืช ืžืชื•ืงื ื•ืช

ื ื•ืฆืจื• ืžื”ื“ื•ืจื•ืช ืžืชืงื ื•ืช ืฉืœ ืฉืคืช ื”ืชื›ื ื•ืช Ruby 3.1.2, 3.0.4, 2.7.6, 2.6.10, ืฉื‘ื”ืŸ ื‘ื•ื˜ืœื• ืฉืชื™ ื ืงื•ื“ื•ืช ืชื•ืจืคื”:

  • CVE-2022-28738 - ื–ื™ื›ืจื•ืŸ ืคื ื•ื™ ื›ืคื•ืœ (ื›ืคื•ืœ ื—ื•ืคืฉื™) ื‘ืงื•ื“ ื”ื™ื“ื•ืจ ืฉืœ ื‘ื™ื˜ื•ื™ ืจื’ื•ืœืจื™ ื”ืžืชืจื—ืฉ ื‘ืขืช ื”ืขื‘ืจืช ืžื—ืจื•ื–ืช ื‘ืขืœืช ืžื‘ื ื” ืžื™ื•ื—ื“ ื‘ืขืช ื™ืฆื™ืจืช ืื•ื‘ื™ื™ืงื˜ Regexp. ื ื™ืชืŸ ืœื ืฆืœ ืืช ื”ืคื’ื™ืขื•ืช ืื ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื ืชื•ื ื™ื ื—ื™ืฆื•ื ื™ื™ื ืœื ืžืื•ืžืชื™ื ื‘ืื•ื‘ื™ื™ืงื˜ Regexp.
  • CVE-2022-28739 - ื”ืฆืคืช ืžืื’ืจ ื‘ืžื—ืจื•ื–ืช ืœืงื•ื“ ื”ืžืจื” ืœืฆื•ืฃ. ื”ืคื’ื™ืขื•ืช ืขืœื•ืœื” ืœื”ื™ื•ืช ืžื ื•ืฆืœืช ื›ื“ื™ ืœืงื‘ืœ ื’ื™ืฉื” ืœืชื•ื›ืŸ ื”ื–ื™ื›ืจื•ืŸ ื‘ืขืช โ€‹โ€‹ื˜ื™ืคื•ืœ ื‘ื ืชื•ื ื™ื ื—ื™ืฆื•ื ื™ื™ื ืœื ืžืื•ืžืชื™ื ื‘ืฉื™ื˜ื•ืช ื›ื’ื•ืŸ Kernel#Float ื•-String#to_f.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”