Bug 1395796 - Rebase to the latest Ruby 2.3 point release
Summary: Rebase to the latest Ruby 2.3 point release
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Red Hat Software Collections
Classification: Red Hat
Component: ruby
Version: rh-ruby23
Hardware: Unspecified
OS: Unspecified
unspecified
unspecified
Target Milestone: ---
: 3.1
Assignee: Pavel Valena
QA Contact: BaseOS QE - Apps
URL:
Whiteboard:
Depends On:
Blocks: 1549649
TreeView+ depends on / blocked
 
Reported: 2016-11-16 17:09 UTC by Vít Ondruch
Modified: 2019-06-19 11:02 UTC (History)
7 users (show)

Fixed In Version:
Doc Type: Rebase: Bug Fixes and Enhancements
Doc Text:
Rebase package(s) to version: 2.3.6 Highlights, important fixes, or notable enhancements: Upgrade to rubygems 2.5.2.2 Upgrade to molinillo 0.4.1 Upgrade to json 1.8.3.1 Upgrade to minitest 5.8.5 Upgrade to psych 2.1.0.1
Clone Of: 1280296
: 1549649 (view as bug list)
Environment:
Last Closed: 2019-06-19 11:02:04 UTC
Target Upstream Version:
Embargoed:


Attachments (Terms of Use)

Description Vít Ondruch 2016-11-16 17:09:06 UTC
New Ruby 2.3 release is available. We should consider rebase.

https://www.ruby-lang.org/en/news/2016/11/15/ruby-2-3-2-released/

Comment 4 Pavel Valena 2017-09-15 16:28:35 UTC
Latest Ruby 2.3 release:
https://www.ruby-lang.org/en/news/2017/09/14/ruby-2-3-5-released/

Contains fixes for:
 - CVE-2017-0898: Buffer underrun vulnerability in Kernel.sprintf
 - CVE-2017-10784: Escape sequence injection vulnerability in the Basic authentication of WEBrick
 - CVE-2017-14033: Buffer underrun vulnerability in OpenSSL ASN1 decode
 - CVE-2017-14064: Heap exposure in generating JSON
 - Multiple vulnerabilities in RubyGems

Comment 5 Vít Ondruch 2017-12-15 09:02:38 UTC
Ruby 2.3.6 is available:

https://www.ruby-lang.org/en/news/2017/12/14/ruby-2-3-6-released/


Note You need to log in before you can comment on or make changes to this bug.