It was discovered that Ruby RDoc incorrectly parsed certain YAML files. If a user or automated system were tricked into parsing a specially crafted .rdoc_options file, a remote attacker could possibly use this issue to execute arbitrary code. (CVE-2024-27281)
It was discovered that the Ruby regex compiler incorrectly handled certain memory operations. A remote attacker could possibly use this issue to obtain sensitive memory contents. (CVE-2024-27282)
{ "binaries": [ { "binary_version": "3.2.3-1ubuntu0.24.04.1", "binary_name": "libruby3.2" }, { "binary_version": "3.2.3-1ubuntu0.24.04.1", "binary_name": "ruby3.2" }, { "binary_version": "3.2.3-1ubuntu0.24.04.1", "binary_name": "ruby3.2-dev" } ], "availability": "No subscription required" }