ALSA-2025:4488

Source
https://errata.almalinux.org/9/ALSA-2025-4488.html
Import Source
https://github.com/AlmaLinux/osv-database/blob/master/advisories/almalinux9/ALSA-2025:4488.json
JSON Data
https://api.test.osv.dev/v1/vulns/ALSA-2025:4488
Related
Published
2025-05-06T00:00:00Z
Modified
2025-05-06T14:32:01Z
Summary
Moderate: ruby:3.1 security update
Details

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.

Security Fix(es):

  • rexml: DoS vulnerability in REXML (CVE-2024-39908)
  • rexml: rubygem-rexml: DoS when parsing an XML having many specific characters such as whitespace character, >] and ]> (CVE-2024-41123)
  • rexml: DoS vulnerability in REXML (CVE-2024-41946)
  • rexml: DoS vulnerability in REXML (CVE-2024-43398)
  • CGI: ReDoS in CGI::Util#escapeElement (CVE-2025-27220)
  • CGI: Denial of Service in CGI::Cookie.parse (CVE-2025-27219)
  • uri: userinfo leakage in URI#join, URI#merge and URI#+ (CVE-2025-27221)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

References

Affected packages

AlmaLinux:9 / rubygem-mysql2

Package

Name
rubygem-mysql2
Purl
pkg:rpm/almalinux/rubygem-mysql2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-1.module_el9.1.0+8+503f6fbd

AlmaLinux:9 / rubygem-mysql2-doc

Package

Name
rubygem-mysql2-doc
Purl
pkg:rpm/almalinux/rubygem-mysql2-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.5.4-1.module_el9.1.0+8+503f6fbd

AlmaLinux:9 / rubygem-pg

Package

Name
rubygem-pg
Purl
pkg:rpm/almalinux/rubygem-pg

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.5-1.module_el9.1.0+8+503f6fbd

AlmaLinux:9 / rubygem-pg-doc

Package

Name
rubygem-pg-doc
Purl
pkg:rpm/almalinux/rubygem-pg-doc

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1.3.5-1.module_el9.1.0+8+503f6fbd