[ubuntu/focal-updates] ruby2.7 2.7.0-5ubuntu1.15 (Accepted)

Ubuntu Archive Robot ubuntu-archive-robot at lists.canonical.com
Thu Nov 21 04:29:16 UTC 2024


ruby2.7 (2.7.0-5ubuntu1.15) focal-security; urgency=medium

  * SECURITY UPDATE: denial or service in REXML
    - debian/patches/CVE-2024-35176_39908_41123-*.patch: Read quoted
      attributes in chunks
    - debian/patches/CVE-2024-41946.patch: Add support for XML entity
      expansion limitation in SAX and pull parsers
    - debian/patches/CVE-2024-49761.patch: fix a bug that &#0x...; is
      accepted as a character reference
    - CVE-2024-35176
    - CVE-2024-39908
    - CVE-2024-41123
    - CVE-2024-41946
    - CVE-2024-49761
  * d/control and d/rules: use gcc-10 for build on riscv64 arch

Date: 2024-11-20 10:18:11.728225+00:00
Changed-By: Nishit Majithia <nishit.majithia at canonical.com>
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/ruby2.7/2.7.0-5ubuntu1.15
-------------- next part --------------
Sorry, changesfile not available.


More information about the Focal-changes mailing list