Ubuntu alert USN-7735-1 (rubygems)
From: | noreply+usn-bot@canonical.com | |
To: | ubuntu-security-announce@lists.ubuntu.com | |
Subject: | [USN-7735-1] RubyGems vulnerabilities | |
Date: | Thu, 04 Sep 2025 09:08:48 +0000 | |
Message-ID: | <E1uu5xY-0007PA-OI@lists.ubuntu.com> |
========================================================================== Ubuntu Security Notice USN-7735-1 September 03, 2025 rubygems vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 25.04 - Ubuntu 22.04 LTS Summary: Several security issues were fixed in RubyGems. Software Description: - rubygems: package management framework for Ruby libraries/applications Details: It was discovered that RubyGems incorrectly handled certain regular expressions. An attacker could use this issue to cause RubyGems to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2023-28755) It was discovered that RubyGems incorrectly handled decompressed domain names within a DNS packet. An attacker could use this issue to cause RubyGems to crash, resulting in a denial of service. This issue only affected Ubuntu 25.04. (CVE-2025-24294) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 25.04 ruby-rubygems 3.6.3-1ubuntu0.1 Ubuntu 22.04 LTS ruby-rubygems 3.3.5-2ubuntu1.1 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7735-1 CVE-2023-28755, CVE-2025-24294 Package Information: https://launchpad.net/ubuntu/+source/rubygems/3.6.3-1ubun... https://launchpad.net/ubuntu/+source/rubygems/3.3.5-2ubun...
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEE+8neBLO2Hp/ppPlOcpJm3tlzhgEFAmi5VkwACgkQcpJm3tlz hgHeeQ/9F5ueBc3lnuq99CNSvmpSNjtTHVH51bEsKSZ4T4V4PTbxJegUIWbv3WAY nm9Zfwm8PNTrOXzj0oga/oANmpGaCNkF+bCL/8/Ta4hNNY0CGAZxmjdfBkj2XsBM HFMlPkvNYKKUqyndx8J8y6VZLR+afSnbEMnGNuRzYnY8lBRr4q1WsnrO571jRvjH MYxTDAyLf7x3Yykivxq3bMwnbGXtJOwDtbSbFw4o4ilFvA19fL4CVrvsE8m1GvDG sF7A6z/RlXIizRRC7mfbl6SYQAmw7CgcaM2HyMxF7bLv8/ZWE8tDIufZMc7bCAqP lnMxg87oGirM3fMp8bWhKguaETFTgUK0fvS5dQKjT8SxKA+XeBXUYxGJf4KmmBFM Z0r86Tw3yoUGhzBkmUNNGZR2o8mFJZHADynSmlfMRQtFapbgq6fz/qZ2eh4wRLpr fHFU7u9qLxIxr78oUxoF5eIaE0fMCxwDFjKGf0VdiUAKiNues55k06sjAUYk6qYX +VrTRs7QJi1zBXu5QDnrnAStzRM5ejLuisYv00nvUK4AQU+PtimnDbYQJVraz6TR MItRnFNsqfvTD1UOW3QFiE95KBp0FrS4uDp7/Kr7wxa4IFYqrZrmLVvQ/cVZx7Zq 7iu4XXJdc39oXaxbe88F4GSpitXbylhjNEIZeaTaHFzbjIsisBs= =omUD -----END PGP SIGNATURE-----