[ubuntu/xenial-security] ruby2.3 2.3.1-2~16.04.6 (Accepted)
Leonidas S. Barbosa
leo.barbosa at canonical.com
Wed Jan 31 14:13:08 UTC 2018
ruby2.3 (2.3.1-2~16.04.6) xenial-security; urgency=medium
* SECURITY UPDATE: fails to validade specification names
- debian/patches/CVE-2017-0901-0902.patch: fix this.
- CVE-2017-0901
* SECURITY UPDATE: vulnerable to a DNS hijacking
- debian/patches/CVE-2017-0901-0902.patch fix this.
- CVE-2017-0902
* SECURITY UPDATE: possible remote code execution
- debian/patches/CVE-2017-0903.patch: whitelist classes
and symbols that are in Gem spec YAML in lib/rubygems.rb,
lib/rubygens/config_file.rb, lib/rubygems/package.rb,
lib/rubygems/package/old.rb, lib/rubygems/safe_yaml.rb,
lib/rubygems/specification.rb.
- CVE-2017-0903
Date: 2018-01-30 18:37:18.902031+00:00
Changed-By: leo.barbosa at canonical.com (Leonidas S. Barbosa)
Maintainer: Antonio Terceiro <antonio.terceiro at linaro.org>
https://launchpad.net/ubuntu/+source/ruby2.3/2.3.1-2~16.04.6
-------------- next part --------------
Sorry, changesfile not available.
More information about the Xenial-changes
mailing list