| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | ruby: Fix CVE-2023-36617 | Mingli Yu | 2023-08-01 | 1 | -0/+2 |
| | | | | | | | | | | | | | | Backport two patches [1] [2] to fix CVE-2023-36617 [3]. [1] https://github.com/ruby/uri/commit/9010ee2536adda10a0555ae1ed6fe2f5808e6bf1 [2] https://github.com/ruby/uri/commit/9d7bcef1e6ad23c9c6e4932f297fb737888144c8 [3] https://www.ruby-lang.org/en/news/2023/06/29/redos-in-uri-CVE-2023-36617/ (From OE-Core rev: 403a24f02600e2462e8ccfbb42651e15e002bd2e) Signed-off-by: Mingli Yu <mingli.yu@windriver.com> Signed-off-by: Steve Sakoman <steve@sakoman.com> | ||||
| * | ruby: upgrade 3.2.1 -> 3.2.2 | Wang Mingyu | 2023-05-10 | 1 | -0/+144 |
| Ruby 3.1.2 CVE-2022-28738: Double free in Regexp compilation.. CVE-2022-28739: Buffer overrun in String-to-Float conversion.. (From OE-Core rev: f1741f1b2fe10d62331a11df6bbd312ae71bffa5) Signed-off-by: Wang Mingyu <wangmy@fujitsu.com> Signed-off-by: Alexandre Belloni <alexandre.belloni@bootlin.com> (cherry picked from commit b261bc704839b12769118f6f1c4207f3d19fe4fd) Signed-off-by: Steve Sakoman <steve@sakoman.com> | |||||
