INFSA-2024:10860: ruby:3.1 security update

Information about definition

Identificator: INFSA-2024:10860

Type: security

Release date: 2025-07-14 20:28:41 UTC

Information about package

Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.

Vulnerabilities description

  • CVE-2024-49761

    A flaw was found in the REXML XML toolkit for Ruby. Parsing XML data containing a large number of digits between &# and x...; in a hex numeric character reference (&#x...;) can trigger a regular expression denial of service (ReDoS) condition, leading to a denial of service.

Severity level

CVE Score CVSS 2.0 Score CVSS 3.x Score CVSS 4.0
no information 7.5 no information
Critical, important, moderate, low

Updated packages