Path to this page:
Subject: CVS commit: pkgsrc/lang
From: Takahiro Kambe
Date: 2024-04-25 16:51:54
Message id: 20240425145154.B8284FA2C@cvs.NetBSD.org
Log Message:
lang/ruby31-base: update to 3.1.5
This is security release. Note CVE-2024-27280 and CVE-2024-27281 were
already fixed by ruby31-base-3.1.4nb3.
3.1.5 (2024-04-23)
Security release.
* CVE-2024-27282: Arbitrary memory address read vulnerability with Regex
search
* CVE-2024-27281: RCE vulnerability with .rdoc_options in RDoc
* CVE-2024-27280: Buffer overread vulnerability in StringIO
Files: