[CLSA-2025:1745053071] ruby: Fix of CVE-2024-49761
Type:
security
Severity:
Important
Release date:
2025-04-19 08:57:56 UTC
Description:
- CVE-2024-49761: parse XML with many digits in hex numeric character reference (&#x...) to fix ReDoS vulnerability in REXML
Updated packages:
  • ruby-3.0.4-160.el9_0.tuxcare.els2.i686.rpm
    sha:02403e7670813613ae6ffccd1ca6efbd1d68851c929d2625d135a8a1bf623a26
  • ruby-3.0.4-160.el9_0.tuxcare.els2.x86_64.rpm
    sha:897530c69acc728649ed018fae5ab8e7ae8bd9c332de7d5149ab327872dc9e75
  • ruby-default-gems-3.0.4-160.el9_0.tuxcare.els2.noarch.rpm
    sha:f780c709eb6d9c991c03c530d5d176d4d0930b0d784ec998adedab618866bc04
  • ruby-devel-3.0.4-160.el9_0.tuxcare.els2.i686.rpm
    sha:fb070eca748fe9d0a75a2f69f013c1385275d625cf020a75c3e4f7845468bebf
  • ruby-devel-3.0.4-160.el9_0.tuxcare.els2.x86_64.rpm
    sha:ebc02568aaffd22eeafa1344bd42df2694f57119df27b5f92c76eda1e36dc70b
  • ruby-doc-3.0.4-160.el9_0.tuxcare.els2.noarch.rpm
    sha:2c5901247e9bfaa407802e03ebdf7e93917826a683bc33b617982474149d401c
  • ruby-libs-3.0.4-160.el9_0.tuxcare.els2.i686.rpm
    sha:a624933e9a24f98aaa8ab576a459fe1df2e49d45d8a08116da4d2caec447331b
  • ruby-libs-3.0.4-160.el9_0.tuxcare.els2.x86_64.rpm
    sha:318e3faac29ad45bf5a26def78e3df1dab5dbbc4edf9bf09896643a5306c829a
  • rubygem-bigdecimal-3.0.0-160.el9_0.tuxcare.els2.i686.rpm
    sha:55fed9718ead277b09667cd41f859308b23118d2e944daa070c4e368048aada3
  • rubygem-bigdecimal-3.0.0-160.el9_0.tuxcare.els2.x86_64.rpm
    sha:ad5a3bb7a11cc28e6cdf8211c477901e86057bb3faa0412b511a1cb48e79990e
  • rubygem-bundler-2.2.33-160.el9_0.tuxcare.els2.noarch.rpm
    sha:45a33e5b91e96cd0761940fc7352b6abd190082eef76a30bc0e93b97b4f5bc80
  • rubygem-io-console-0.5.7-160.el9_0.tuxcare.els2.i686.rpm
    sha:46173dcb49654b9b05c735b92da465e18102866cf6191aebaa0e03311c11aa59
  • rubygem-io-console-0.5.7-160.el9_0.tuxcare.els2.x86_64.rpm
    sha:c9f80890a14182cca98d46d3cf0930f7a562dd3667de18b7d3ec49b65e75df1d
  • rubygem-irb-1.3.5-160.el9_0.tuxcare.els2.noarch.rpm
    sha:aa44d894ce94e9a11a92b2d97c0e178def555d050c4f25d25577149783b23401
  • rubygem-json-2.5.1-160.el9_0.tuxcare.els2.i686.rpm
    sha:9f4c73dc8b0e9e233b19aabcf50043bcc18d33370da1ce8a92891f417b26b838
  • rubygem-json-2.5.1-160.el9_0.tuxcare.els2.x86_64.rpm
    sha:06352925bc3e3c8c04f41488fcbc44cf511669066c64b09bd1d449f456259730
  • rubygem-minitest-5.14.2-160.el9_0.tuxcare.els2.noarch.rpm
    sha:38baffb77258806e28f9246ba872886a6b0fd938cabc1f0f211f0264b7746b3f
  • rubygem-power_assert-1.2.0-160.el9_0.tuxcare.els2.noarch.rpm
    sha:93c31aa06a069911b677caf09e621578bd34a4836717ce6f3259488db98e37a5
  • rubygem-psych-3.3.2-160.el9_0.tuxcare.els2.i686.rpm
    sha:269bded6599a8b72a9d80f1991b039951381c418d86f92fbffd3d05f2e2b9d4e
  • rubygem-psych-3.3.2-160.el9_0.tuxcare.els2.x86_64.rpm
    sha:82795f0f9c09271e623452a9665b12b6e073e5c3acf0de21077d03010428e8c8
  • rubygem-rake-13.0.3-160.el9_0.tuxcare.els2.noarch.rpm
    sha:95c2fd1006c8232a988a6901052f4dd0c9c5a5442dfe5ca90165f3c2c1e4c316
  • rubygem-rbs-1.4.0-160.el9_0.tuxcare.els2.noarch.rpm
    sha:267b684c3293cc5b68cb934dd64cf1a3489092151d52da881d650d8753183c21
  • rubygem-rdoc-6.3.3-160.el9_0.tuxcare.els2.noarch.rpm
    sha:ec1202098b898b4a3d672a8cd99d3454d3fa1ca7dbb405e3052d665ae29ff9ac
  • rubygem-rexml-3.2.5-160.el9_0.tuxcare.els2.noarch.rpm
    sha:5107564406c5a55f1090a9f2130e3af8fbee4ec16ef3cde20b2e78bb6433e566
  • rubygem-rss-0.2.9-160.el9_0.tuxcare.els2.noarch.rpm
    sha:a797d8f9748f4034d3abce2f39631e2a5e91b433ca9e9618e0e97cbba83d39b5
  • rubygem-test-unit-3.3.7-160.el9_0.tuxcare.els2.noarch.rpm
    sha:bcece019aea34d744dafa3f932d9582f48b66f549224387dd3ccb15ec8c93723
  • rubygem-typeprof-0.15.2-160.el9_0.tuxcare.els2.noarch.rpm
    sha:c435aca3296202c8e43edaa8a14bc6959d0cd8652661d8580574d789c5922f44
  • rubygems-3.2.33-160.el9_0.tuxcare.els2.noarch.rpm
    sha:05ee1808567be15349dc62eaeb3ed0fbcef4ddc333c16eb9069921c79746edc5
  • rubygems-devel-3.2.33-160.el9_0.tuxcare.els2.noarch.rpm
    sha:1b2f334fb15c2871ccab238423934969dabea47431a4ef0a003e789bf2fae71b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.