Kururamisa kuburitswa kweRuby 3.1.2, 3.0.4, 2.7.6, 2.6.10 ine vulnerabilities yakagadziriswa

Kururamisa kuburitswa kweRuby programming language 3.1.2, 3.0.4, 2.7.6, 2.6.10 kwakagadzirwa, umo kusagona kuviri kwakabviswa:

  • CVE-2022-28738 ndeye yakapetwa-yemahara mune yakajairwa kutaura yekubatanidza kodhi inoitika kana tambo yakagadzirwa yakapfuura kana ichigadzira chinhu cheRegexp. Kusagadzikana kunogona kushandiswa nekushandisa isina kuvimbika data rekunze muchinhu cheRegexp.
  • CVE-2022-28739 - Buffer kufashukira mune tambo-ku-kuya-yangarara yekushandura kodhi. Kusagadzikana kunogona kushandiswa kuwana mukana wemukati mendangariro kana uchigadzira isina kuvimbika data rekunze munzira dzakaita seKernel#Float uye String#to_f.

Source: opennet.ru

Voeg