Project

General

Profile

Actions

Bug #20385

closed

Backport CVE-2024-27280

Added by hsbt (Hiroshi SHIBATA) about 1 year ago. Updated 11 months ago.

Status:
Closed
Assignee:
-
Target version:
-
[ruby-core:117280]

Description

I disclosed https://www.ruby-lang.org/en/news/2024/03/21/buffer-overread-cve-2024-27280/ today.

This StringIO versions should be backported in the next release.

Actions #1

Updated by hsbt (Hiroshi SHIBATA) 11 months ago

  • Backport changed from 3.0: REQUIRED, 3.1: REQUIRED, 3.2: DONTNEED, 3.3: DONTNEED to 3.0: DONE, 3.1: DONE, 3.2: DONTNEED, 3.3: DONTNEED
Actions

Also available in: Atom PDF

Like0
Like0