{"id":"MGASA-2025-0290","summary":"Updated ruby packages fix security vulnerabilities","details":"Net::IMAP vulnerable to possible DoS by memory exhaustion.\n(CVE-2025-25186)\nIn the CGI gem before 0.4.2 for Ruby, the CGI::Cookie.parse method in\nthe CGI library contains a potential Denial of Service (DoS)\nvulnerability. The method does not impose any limit on the length of the\nraw cookie value it processes. This oversight can lead to excessive\nresource consumption when parsing extremely large cookies.\n(CVE-2025-27219)\nIn the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of\nService (ReDoS) vulnerability exists in the Util#escapeElement method.\n(CVE-2025-27220)\nIn the URI gem before 1.0.3 for Ruby, the URI handling methods\n(URI.join, URI#merge, URI#+) have an inadvertent leakage of\nauthentication credentials because userinfo is retained even after\nchanging the host. (CVE-2025-27221)\n","modified":"2026-04-16T04:44:45.047201304Z","published":"2025-11-13T23:37:22Z","upstream":["CVE-2025-25186","CVE-2025-27219","CVE-2025-27220","CVE-2025-27221"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2025-0290.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=34179"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-7418-1"}],"affected":[{"package":{"name":"ruby","ecosystem":"Mageia:9","purl":"pkg:rpm/mageia/ruby?arch=source&distro=mageia-9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.1.5-47.mga9"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2025-0290.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}