CVE-2023-28755: ReDoS vulnerability in URI

We have released the uri gem version 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1 that has a security fix for a ReDoS vulnerability.
This vulnerability has been assigned the CVE identifier CVE-2023-28755.

Details

A ReDoS issue was discovered in the URI component. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects.

The uri gem version 0.12.0, 0.11.0, 0.10.1, 0.10.0 and all versions prior 0.10.0 are vulnerable for this vulnerability.

Recommended action

We recommend to update the uri gem to 0.12.1. In order to ensure compatibility with bundled version in older Ruby series, you may update as follows instead:

  • For Ruby 2.7: Update to uri 0.10.0.1
  • For Ruby 3.0: Update to uri 0.10.2
  • For Ruby 3.1: Update to uri 0.11.1
  • For Ruby 3.2: Update to uri 0.12.1

You can use gem update uri to update it. If you are using bundler, please add gem "uri", ">= 0.12.1" (or other version mentioned above) to your Gemfile.

Affected versions

  • uri gem 0.12.0
  • uri gem 0.11.0
  • uri gem 0.10.1
  • uri gem 0.10.0 or before

Credits

Thanks to Dominic Couture for discovering this issue.

History

  • Originally published at 2023-03-28 01:00:00 (UTC)
  • Update Affected versions at 2023-03-28 02:00:00 (UTC)

Posted by hsbt on 28 Mar 2023

Windows needs to stop showing tabloid news

Did you know that pigs eat humans “far more often than people expect?” If not, surely you must have heard the important, breaking news that a priest “died” in 2016, went to Hell briefly and returned to inform the rest of us that demons like to play Rhianna’s Umbrella song over and over again. If you aren’t aware of these important news stories then maybe you haven’t been spending enough time using Windows’ search box and widgets section, which at least for me, are filled to the brim with tabloid trash headlines. The stories come courtesy of Microsoft’s MSN content network, which syndicates content from hundreds of web publishers: some reputable, some less so. Full disclosure: Our parent company, Future Plc, has a syndication agreement with MSN and many of its sites, including Tom’s Hardware, occasionally have articles appear on the network. What’s problematic here, though, is not that MSN syndicates content but that it often pushes the equivalent of the Weekly World News table of contents right into the Windows operating system where it can be hard to avoid. Actions have consequences. If you choose to use Windows, you choose to get fed garbage all over your operating system in the form of ads and tabloid news.

Mah e Ramzan Aur Khawateen – Naimat e Iftar – Shan e Ramzan – 27th March 2023 – ARY Qtv

Naimat e Iftar – Mah e Ramzan Aur Khawateen – Shan e Ramzan

Topic: Islam Ka Falsafa e Ibadat

Host: Syeda Nida Naseem

Guest: Prof. Sadia Ansari, Imtiyaz Javed Khakvi, Sehar Azam

Subscribe Here: https://bit.ly/3dh3Yj1

#ShaneRamzan2023 #NaimateIftar #MaheRamzanAurKhawateen

Official Facebook: https://www.facebook.com/ARYQTV/
Official Website: https://aryqtv.tv/
Watch ARY Qtv Live: http://live.aryqtv.tv/
Programs Schedule: https://aryqtv.tv/schedule/
Islamic Information: https://bit.ly/2MfIF4P
Android App: https: //bit.ly/33wgto4
Ios App: https: https://apple.co/2v3zoXW

Miami: Alcaraz et Sabalenka en contrôle

Les favoris du Masters 1000 de Miami, l’Espagnol Carlos Alcaraz et la Bélarusse Aryna Sabalenka, se sont facilement imposés dimanche, et l’Américain Taylor Fritz et le Danois Holger Rune ont validé leur ticket et s’affronteront en huitièmes de finale.

How to Create a Blog in 2023 | Most Important Blogger Settings | Full Details in Telugu…

#saikumartechy #bloggingtutorial #howtostartablog

How to Create a Blog in 2023 | Most Important Blogger Settings | Full Details in Telugu | @SaikumarTechy

Hi, thanks for watching our video about How to Create a Blog in 2023
In this video we’ll walk you through:
Blog Creation Tips
Blogger settings explained
How to start a blog

Robots.txt File:
http://bit.ly/40yGKML

మీకు ఏ వీడియో కావాలన్నా నన్ను కాంటాక్ట్ చేస్తే నేను కచ్చితంగా ఆ వీడియో చేస్తాను.

Check out our channel here:
https://www.youtube.com/@SaikumarTechy
Don’t forget to subscribe!

FIND US AT;
https://saikumartechy.com

Join Whatsapp Group For Your Doubts❓
https://chat.whatsapp.com/EkxKGhi1tlI…

FOLLOW US ON SOCIAL;
Get updates or reach out to Get updates on our Social Media Profiles!
☣️Twitter:
https://twitter.com/Saikumartechy

☣️Facebook: https://www.facebook.com/saikumartechy

☣️Instagram: https://www.instagram.com/saikumar_techy

☣️Telegram:
https://t.me/saikumartechy

☣️Share chat: https://b.sharechat.com/L6sgfRITDeb

☣️Website :- https://saikumartechy.com

DAILY JOB UPDATES
follow this website :-
https://bharatbadi.com

TOPICS COVERED:-
How to start a blog 2023
Blogging for beginners
Telugu blog creation guide
Best blogger settings to use
Telugu blog writing tips and tricks

#saikumartechy #saikumar #blogger
#howtostartablog #bloggingtutorial

For Any Copyrighted matters Contact us:
contact@saikumartechy.com

Disclaimer- Some contents are used for educational
purpose under fair use. Copyright Disclaimer Under
Section 107 of the Copyright Act 1976, allowance is
made for “fair use” for purposes such as criticism,
comment, news reporting, teaching, scholarship,
and research. Fair use is a use permitted by
copyright statute that might otherwise be infringing.
Non-profit, educational or personal use tips the
balance in favor of fair use.

:- Images used in this video thumbnail belongs to respected owners , not mine thanks to them.

N͟O͟ C͟O͟P͟Y͟R͟I͟G͟H͟T͟ I͟N͟F͟R͟I͟N͟G͟E͟M͟E͟N͟T͟ I͟N͟T͟E͟N͟D͟E͟D͟

COPYRIGHT NOTICE:-
Please feel free to leave Me a notice if you find this upload inappropriate. Contact me personally if you are against an upload wish you may have rights to the music, instead of contacting YouTube about a copyright infringement.

FreeBSD 13.2-RC5 Available

The fifth RC build for the FreeBSD 13.2 release cycle is now available. ISO images for the amd64, i386, powerpc, powerpc64, powerpc64le, powerpcspe, armv6, armv7, aarch64, and riscv64 architectures are FreeBSD mirror sites.