Opened 12 months ago

Closed 12 months ago

Last modified 8 months ago

#22245 closed enhancement (fixed)

ruby-3.4.7

Reported by: Bruce Dubbs Owned by: Bruce Dubbs
Priority: elevated Milestone: 13.0
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

New point version.

Change History (5)

comment:1 by Bruce Dubbs, 12 months ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Douglas R. Reno, 12 months ago

Priority: normal → elevated

This is a security fix release for CVE-2025-61594 in the 'uri' gem that's bundled with Ruby. This is a credential leakage problem.

Details from the announcement of the security vulnerability upstream:

CVE-2025-61594: URI Credential Leakage Bypass over CVE-2025-27221

In affected URI version, a bypass exists for the fix to CVE-2025-27221 that can expose 
user credentials.

This vulnerability has been assigned the CVE identifier CVE-2025-61594. We recommend 
upgrading the uri gem.

Details

When using the + operator to combine URIs, sensitive information like passwords from the 
original URI can be leaked, violating RFC3986 and making applications vulnerable to 
credential exposure.

Please update URI gem to version 0.12.5, 0.13.3, 1.0.4 or later.

Affected versions

    uri gem versions < 0.12.5, 0.13.0 to 0.13.2 and 1.0.0 to 1.0.3.

The rest of the release notes are:

What's Changed

    Merge URI-1.0.4 for Ruby 3.4 by hsbt · Pull Request #14757
    Bug #21313: it in rescue/ensure on prism - Ruby - Ruby Issue Tracking System
    [3.4] compile.c: Handle anonymous variables in outer_variable_cmp by byroot · Pull 
Request #13493
    Bug #21610: Use ec->interrupt_mask to prevent interrupts. - Ruby - Ruby Issue 
Tracking System
    Bug #21611: Ruby 3.4.6 can't be built with GCC 15.2.1 - Ruby - Ruby Issue Tracking 
System
    Bug #21342: Segfault: invalid keeping_mutexes when using Mutex in Thread then Fiber 
after GC - Ruby - Ruby Issue Tracking System
    Bug #21569: [armv7, musl] SIGBUS in ibf_load_object_float due to unaligned VFP 
double load when reading IBF - Ruby - Ruby Issue Tracking System
    Bug #21568: Requiring core libraries when already requiring multiple user defined 
libraries with the same name can error - Ruby - Ruby Issue Tracking System

comment:3 by Bruce Dubbs, 12 months ago

Resolution: → fixed
Status: assigned → closed

Fixed at commits

00e1ef790e Update to unixODBC-2.3.14.
effc98c679 Update to ruby-3.4.7 (Security update).

comment:4 by Douglas R. Reno, 12 months ago

SA-12.4-019 issued

comment:5 by Bruce Dubbs, 8 months ago

Milestone: 12.5 → 13.0

Milestone renamed

Note: See TracTickets for help on using tickets.