[Git][security-tracker-team/security-tracker][master] Triage CVE-2022-28739 in ruby2.3 for stretch LTS.

Chris Lamb (@lamby) lamby at debian.org
Wed Apr 27 17:08:57 BST 2022



Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d03435d4 by Chris Lamb at 2022-04-27T09:08:39-07:00
Triage CVE-2022-28739 in ruby2.3 for stretch LTS.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2852,6 +2852,7 @@ CVE-2022-28739 [Buffer overrun in String-to-Float conversion]
 	- ruby2.5 <removed>
 	[buster] - ruby2.5 <postponed> (Minor issue, fix with next Ruby security release)
 	- ruby2.3 <removed>
+	[stretch] - ruby2.3 <postponed> (Minor issue; fix in next LTS release)
 	NOTE: https://github.com/ruby/ruby/commit/69f9992ed41920389d4185141a14f02f89a4d306 (v2_6_10)
 	NOTE: https://github.com/ruby/ruby/commit/c9c2245c0a25176072e02db9254f0e0c84c805cd (v2_7_6)
 	NOTE: https://github.com/ruby/ruby/commit/3fa771ddedac25560be57f4055f1767e6c810f58 (v3_0_4)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d03435d40d0b6fe44840edef005247fcb0fc59e2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d03435d40d0b6fe44840edef005247fcb0fc59e2
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20220427/86ca02aa/attachment.htm>


More information about the debian-security-tracker-commits mailing list