ELA-1149-1 ruby2.3 security update

multiple vulnerabilities

2024-08-13
Packageruby2.3
Version2.3.3-1+deb9u12 (stretch)
Related CVEs CVE-2021-28965 CVE-2021-33621 CVE-2022-28739 CVE-2023-28755 CVE-2023-28756 CVE-2023-36617 CVE-2024-27281 CVE-2024-27282


Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in denial-of-service (DoS), information leak, HTTP response splitting, XML round-trip issues, and remote code execution.



For Debian 9 stretch, these problems have been fixed in version 2.3.3-1+deb9u12.

We recommend that you upgrade your ruby2.3 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.