Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 24 Nov 2021 15:20:04 GMT
From:      Yasuhiro Kimura <yasu@FreeBSD.org>
To:        ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org
Subject:   git: 1ea17b42aea1 - main - security/vuxml: Update affecting packages of 6916ea94-4628-11ec-bbe2-0800270512f4
Message-ID:  <202111241520.1AOFK45s027788@gitrepo.freebsd.org>

next in thread | raw e-mail | index | archive | help
The branch main has been updated by yasu:

URL: https://cgit.FreeBSD.org/ports/commit/?id=1ea17b42aea15e9d2f2a690de22b434e88d9a48a

commit 1ea17b42aea15e9d2f2a690de22b434e88d9a48a
Author:     Yasuhiro Kimura <yasu@FreeBSD.org>
AuthorDate: 2021-11-24 14:48:11 +0000
Commit:     Yasuhiro Kimura <yasu@FreeBSD.org>
CommitDate: 2021-11-24 15:18:56 +0000

    security/vuxml: Update affecting packages of 6916ea94-4628-11ec-bbe2-0800270512f4
    
    This vulnerability also affects ruby ports.
---
 security/vuxml/vuln-2021.xml | 19 +++++++++++++++++++
 1 file changed, 19 insertions(+)

diff --git a/security/vuxml/vuln-2021.xml b/security/vuxml/vuln-2021.xml
index 74463ed364ca..759bb3d203f1 100644
--- a/security/vuxml/vuln-2021.xml
+++ b/security/vuxml/vuln-2021.xml
@@ -166,6 +166,24 @@
   <vuln vid="6916ea94-4628-11ec-bbe2-0800270512f4">
     <topic>rubygem-date -- Regular Expression Denial of Service Vunlerability of Date Parsing Methods</topic>
     <affects>
+      <package>
+	<name>ruby</name>
+	<range><ge>2.6.0,1</ge><lt>2.6.9,1</lt></range>
+	<range><ge>2.7.0,1</ge><lt>2.7.5,1</lt></range>
+	<range><ge>3.0.0,1</ge><lt>3.0.3,1</lt></range>
+      </package>
+      <package>
+	<name>ruby26</name>
+	<range><ge>2.6.0,1</ge><lt>2.6.9,1</lt></range>
+      </package>
+      <package>
+	<name>ruby27</name>
+	<range><ge>2.7.0,1</ge><lt>2.7.5,1</lt></range>
+      </package>
+      <package>
+	<name>ruby30</name>
+	<range><ge>3.0.0,1</ge><lt>3.0.3,1</lt></range>
+      </package>
       <package>
 	<name>rubygem-date</name>
 	<range><lt>3.2.1</lt></range>
@@ -192,6 +210,7 @@
     <dates>
       <discovery>2021-11-15</discovery>
       <entry>2021-11-15</entry>
+      <modified>2021-11-24</modified>
     </dates>
   </vuln>
 



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202111241520.1AOFK45s027788>