Alerts This Week
Warning Icon 1 1,394
Alerts This Week
Warning Icon 1 1,394

Ubuntu 20.04 LTS USN-7256-2 moderate: ruby2.7 denial of service

ubuntu
Calendar Grey February 13, 2025
Dist Ubuntu Esm H88
The latest patch for Ruby on Ubuntu 20.04 LTS addresses a stability issue introduced by USN-7256-1, enhancing service performance and reliability.
USN-7256-1 caused some minor regressions in Ruby

Summary

USN-7256-1 caused some minor regressions in Ruby

Software Description:

- ruby2.7: Object-oriented scripting language

Details:

USN-7256-1 fixed vulnerabilities in Ruby. The update introduced a minor

regression. This update fixes the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that Ruby incorrectly handled parsing of an XML document

that has specific XML characters in an attribute value using REXML gem. An

attacker could use this issue to cause Ruby to crash, resulting in a

denial of service.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
  libruby2.7                      2.7.0-5ubuntu1.17
  ruby2.7                         2.7.0-5ubuntu1.17

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7256-2

https://ubuntu.com/security/notices/USN-7256-1

https://bugs.launchpad.net/ubuntu/+source/ruby2.7/+bug/2097527

Ubuntu Security Notice USN-7256-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here