[ubuntu/bionic-updates] ruby2.5 2.5.1-1ubuntu1.10 (Accepted)
Ubuntu Archive Robot
ubuntu-archive-robot at lists.canonical.com
Wed Jul 21 15:28:37 UTC 2021
ruby2.5 (2.5.1-1ubuntu1.10) bionic-security; urgency=medium
* SECURITY UPDATE: Command injection vulnerability in RDoc
- debian/patches/CVE-2021-31799.patch: fix replace open for File.open
in lib/rdoc/rdoc.rb, test/rdoc/test_rdoc_rdoc.rb.
- CVE-2021-31799
* SECURITY UPDATE: Information leak
- debian/patches/CVE-2021-31810.patch: ignore IP address in PASV
responses by default and add new option use_pasv_ip in lib/net/ftp.rb,
test/net/ftp/test_ftp.rb.
- CVE-2021-31810
* SECURITY UPDATE: Stripping vulnerability
- debian/patches/CVE-2021-32066.patch: fix raising an exception
when a unknow response error happens in
lib/net/imap.rb, test/net/imap/test_imap.rb.
- CVE-2021-32066
* debian/patches/fixing_test_imap.patch: adds start_server to
IMAPTest in order to test_starttls_stripping runs properly.
Date: 2021-07-15 19:13:09.822563+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Signed-By: Ubuntu Archive Robot <ubuntu-archive-robot at lists.canonical.com>
https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-1ubuntu1.10
-------------- next part --------------
Sorry, changesfile not available.
More information about the Bionic-changes
mailing list