ELA-1150-1 ruby2.5 security update

multiple vulnerabilities

2024-08-13
Packageruby2.5
Version2.5.5-3+deb10u7 (buster)
Related CVEs CVE-2023-36617 CVE-2024-27280 CVE-2024-27281 CVE-2024-27282


Several vulnerabilities have been discovered in the interpreter for the Ruby language, which may result in denial-of-service (DoS), information leak, and remote code execution.



For Debian 10 buster, these problems have been fixed in version 2.5.5-3+deb10u7.

We recommend that you upgrade your ruby2.5 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.