[ubuntu/cosmic-security] ruby2.5 2.5.1-5ubuntu4.3 (Accepted)

Leonidas S. Barbosa leo.barbosa at canonical.com
Thu Apr 11 13:18:37 UTC 2019


ruby2.5 (2.5.1-5ubuntu4.3) cosmic-security; urgency=medium

  * SECURITY UPDATE: Delete directory using symlink when decompressing tar,
    Escape sequence injection vulnerability in gem owner, Escape sequence
    injection vulnerability in API response handling, Arbitrary code exec,
    Escape sequence injection vulnerability in errors
    - debian/patches/CVE-2019-8320-25.patch: fix in
      lib/rubygems/command_manager.rb,
      lib/rubygems/commands/owner_command.rb,
      lib/rubygems/gemcutter_utilities.rb,
      lib/rubygems/installer.rb,
      lib/rubygems/package.rb,
      test/rubygems/test_gem_installer.rb,
      test/rubygems/test_gem_package.rb,
      test/rubygems/test_gem_text.rb.
    - CVE-2019-8320
    - CVE-2019-8321
    - CVE-2019-8322
    - CVE-2019-8323
    - CVE-2019-8324
    - CVE-2019-8325

ruby2.5 (2.5.1-5ubuntu4.2) cosmic; urgency=medium

  * d/p/update-cert-{1,2}.patch: update certificates to fix FTBFS. Patches
    prepared by Andreas Hasenack. (LP: #1812669)

Date: 2019-04-02 19:24:17.786295+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
https://launchpad.net/ubuntu/+source/ruby2.5/2.5.1-5ubuntu4.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the Cosmic-changes mailing list