Date: Wed, 24 Nov 2021 15:20:04 GMT From: Yasuhiro Kimura <yasu@FreeBSD.org> To: ports-committers@FreeBSD.org, dev-commits-ports-all@FreeBSD.org, dev-commits-ports-main@FreeBSD.org Subject: git: 1ea17b42aea1 - main - security/vuxml: Update affecting packages of 6916ea94-4628-11ec-bbe2-0800270512f4 Message-ID: <202111241520.1AOFK45s027788@gitrepo.freebsd.org>
next in thread | raw e-mail | index | archive | help
The branch main has been updated by yasu: URL: https://cgit.FreeBSD.org/ports/commit/?id=1ea17b42aea15e9d2f2a690de22b434e88d9a48a commit 1ea17b42aea15e9d2f2a690de22b434e88d9a48a Author: Yasuhiro Kimura <yasu@FreeBSD.org> AuthorDate: 2021-11-24 14:48:11 +0000 Commit: Yasuhiro Kimura <yasu@FreeBSD.org> CommitDate: 2021-11-24 15:18:56 +0000 security/vuxml: Update affecting packages of 6916ea94-4628-11ec-bbe2-0800270512f4 This vulnerability also affects ruby ports. --- security/vuxml/vuln-2021.xml | 19 +++++++++++++++++++ 1 file changed, 19 insertions(+) diff --git a/security/vuxml/vuln-2021.xml b/security/vuxml/vuln-2021.xml index 74463ed364ca..759bb3d203f1 100644 --- a/security/vuxml/vuln-2021.xml +++ b/security/vuxml/vuln-2021.xml @@ -166,6 +166,24 @@ <vuln vid="6916ea94-4628-11ec-bbe2-0800270512f4"> <topic>rubygem-date -- Regular Expression Denial of Service Vunlerability of Date Parsing Methods</topic> <affects> + <package> + <name>ruby</name> + <range><ge>2.6.0,1</ge><lt>2.6.9,1</lt></range> + <range><ge>2.7.0,1</ge><lt>2.7.5,1</lt></range> + <range><ge>3.0.0,1</ge><lt>3.0.3,1</lt></range> + </package> + <package> + <name>ruby26</name> + <range><ge>2.6.0,1</ge><lt>2.6.9,1</lt></range> + </package> + <package> + <name>ruby27</name> + <range><ge>2.7.0,1</ge><lt>2.7.5,1</lt></range> + </package> + <package> + <name>ruby30</name> + <range><ge>3.0.0,1</ge><lt>3.0.3,1</lt></range> + </package> <package> <name>rubygem-date</name> <range><lt>3.2.1</lt></range> @@ -192,6 +210,7 @@ <dates> <discovery>2021-11-15</discovery> <entry>2021-11-15</entry> + <modified>2021-11-24</modified> </dates> </vuln>
Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?202111241520.1AOFK45s027788>