CVE-2023-28755: ReDoS vulnerability in URI

We have released the uri gem version 0.12.1, 0.11.1, 0.10.2 and 0.10.0.1 that has a security fix for a ReDoS vulnerability.
This vulnerability has been assigned the CVE identifier CVE-2023-28755.

Details

A ReDoS issue was discovered in the URI component. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to URI objects.

The uri gem version 0.12.0, 0.11.0, 0.10.1, 0.10.0 and all versions prior 0.10.0 are vulnerable for this vulnerability.

Recommended action

We recommend to update the uri gem to 0.12.1. In order to ensure compatibility with bundled version in older Ruby series, you may update as follows instead:

  • For Ruby 2.7: Update to uri 0.10.0.1
  • For Ruby 3.0: Update to uri 0.10.2
  • For Ruby 3.1: Update to uri 0.11.1
  • For Ruby 3.2: Update to uri 0.12.1

You can use gem update uri to update it. If you are using bundler, please add gem "uri", ">= 0.12.1" (or other version mentioned above) to your Gemfile.

Affected versions

  • uri gem 0.12.0
  • uri gem 0.11.0
  • uri gem 0.10.1
  • uri gem 0.10.0 or before

Credits

Thanks to Dominic Couture for discovering this issue.

History

  • Originally published at 2023-03-28 01:00:00 (UTC)
  • Update Affected versions at 2023-03-28 02:00:00 (UTC)

Posted by hsbt on 28 Mar 2023

Windows needs to stop showing tabloid news

Did you know that pigs eat humans “far more often than people expect?” If not, surely you must have heard the important, breaking news that a priest “died” in 2016, went to Hell briefly and returned to inform the rest of us that demons like to play Rhianna’s Umbrella song over and over again. If you aren’t aware of these important news stories then maybe you haven’t been spending enough time using Windows’ search box and widgets section, which at least for me, are filled to the brim with tabloid trash headlines. The stories come courtesy of Microsoft’s MSN content network, which syndicates content from hundreds of web publishers: some reputable, some less so. Full disclosure: Our parent company, Future Plc, has a syndication agreement with MSN and many of its sites, including Tom’s Hardware, occasionally have articles appear on the network. What’s problematic here, though, is not that MSN syndicates content but that it often pushes the equivalent of the Weekly World News table of contents right into the Windows operating system where it can be hard to avoid. Actions have consequences. If you choose to use Windows, you choose to get fed garbage all over your operating system in the form of ads and tabloid news.

Baš mi se svida – Domaćice sa Bosfora 6 Epizoda

Video by via Dailymotion Source Glumac/GlumicaSerhat TutumluerCeyda DüvenciÖzge ÖzderHale AkınlıBennu YıldırımlarBatuhan KaracakayaSongül ÖdenMelda AratCenk Ertanİlker Kurtİncilay ŞahinMetin BüktelEvrim SolmazServer MutluEce HakimDevrim ÖzderErdal BilingenFurkan Andıç Go to Source

Frente fria acaba com recorde de calor no Sul

Video by via Dailymotion Source A frente fria que ingressou no Rio Grande do Sul neste fim de semana acabou com sequência de dias de calor recorde na Grande Porto Alegre, sem precedente na climatologia de março nos últimos 40 anos na estação de referência histórica da área metropolitana, em Campo Bom, que possui dados … Read more

Nasamsam na mga armas sa compound ni dating Gov. Teves, isinasailalim na sa forensic exam | 24 Oras

Video by via Dailymotion Source 24 Oras is GMA Network’s flagship newscast, anchored by Mike Enriquez, Mel Tiangco and Vicky Morales. It airs on GMA-7 Mondays to Fridays at 6:30 PM (PHL Time) and on weekends at 6:00 PM. For more videos from 24 Oras, visit http://www.gmanetwork.com/24oras. #Nakatutok24Oras Breaking news and stories from the Philippines … Read more

News & Views Live: सावरकरांचा वाद.. तरीही गांधींना ठाकरेंशिवाय पर्याय नाही..Thackeray | Rahul Gandhi

Video by via Dailymotion Source News & Views Live: सावरकरांचा वाद….तरीही गांधींना ठाकरेंशिवाय पर्याय नाही.. | Uddhav Thackeray | Rahul Gandhi | Veer Savarkar #uddhavthackeray #Rahulgandhi #maharashtranews #Lokmat Subscribe to Our Channel https://www.youtube.com/user/LokmatNews?sub_confirmation=1 आमचा video आवडल्यास धन्यवाद. Like, Share and Subscribe करायला विसरू नका! मित्रांसोबत गप्पा मारताना विश्वसनीय, संशोधनावर आधारीत माहिती सादर करायची असेल तर … Read more