ruby2.7 2.7.0-5ubuntu1.6 source package in Ubuntu

Changelog

ruby2.7 (2.7.0-5ubuntu1.6) focal-security; urgency=medium

  * SECURITY UPDATE: Buffer overrun
    - debian/patches/CVE-2021-41816.patch: fix integer overflow making
      sure use of the check in rb_alloc_tmp_buffer2 in
      ext/cgi/escape/escape.c.
    - CVE-2021-41816
  * SECURITY UPDATE: ReDoS vulnerability
    - debian/patches/CVE-2021-41817-*.patch: add length limit option
      for methods that parses date strings and mimic prev behaviour
      in  ext/date/date_core.c, test/date/test_date_parse.rb.
    - CVE-2021-41817
  * SECURITY UPDATE: Mishandles sec prefixes in cookie names
    - debian/patches/CVE-2021-41819.patch: when parsing cookies, only
      decode the values in lib/cgi/cookie.rb, test/cgi/test_cgi_cookie.rb.
    - CVE-2021-41819

 -- Leonidas Da Silva Barbosa <email address hidden>  Thu, 06 Jan 2022 09:34:12 -0300

Upload details

Uploaded by:
Leonidas S. Barbosa
Uploaded to:
Focal
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
ruby
Urgency:
Medium Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ruby2.7_2.7.0.orig.tar.xz 10.2 MiB 317ea23716234b1ca393f3509afa115b98b6a873f6724faffdcaeb04bd6f2935
ruby2.7_2.7.0-5ubuntu1.6.debian.tar.xz 124.6 KiB 27ebad6cf9ebc456c9e4d84bfb191c7bb1754d6df6e70757f367ead4eee0829c
ruby2.7_2.7.0-5ubuntu1.6.dsc 2.5 KiB e42adb47c43de4ef64cf4c623d70736263fe48966445a31f055f315a633f8410

View changes file

Binary packages built by this source

libruby2.7: Libraries necessary to run Ruby 2.7

 Ruby is the interpreted scripting language for quick and easy
 object-oriented programming. It has many features to process text
 files and to do system management tasks (as in perl). It is simple,
 straight-forward, and extensible.
 .
 This package includes the 'libruby-2.7' library, necessary to run Ruby 2.7.
 (API version 2.7.0)

libruby2.7-dbgsym: debug symbols for libruby2.7
ruby2.7: Interpreter of object-oriented scripting language Ruby

 Ruby is the interpreted scripting language for quick and easy
 object-oriented programming. It has many features to process text
 files and to do system management tasks (as in perl). It is simple,
 straight-forward, and extensible.
 .
 In the name of this package, `2.7' indicates the Ruby library compatibility
 version. This package currently provides the `2.7.x' branch of Ruby.

ruby2.7-dbgsym: debug symbols for ruby2.7
ruby2.7-dev: Header files for compiling extension modules for the Ruby 2.7

 Ruby is the interpreted scripting language for quick and easy
 object-oriented programming. It has many features to process text
 files and to do system management tasks (as in perl). It is simple,
 straight-forward, and extensible.
 .
 This package contains the header files and the mkmf library, necessary
 to make extension library for Ruby 2.7. It is also required to build
 many gems.

ruby2.7-doc: Documentation for Ruby 2.7

 Ruby is the interpreted scripting language for quick and easy
 object-oriented programming. It has many features to process text
 files and to do system management tasks (as in perl). It is simple,
 straight-forward, and extensible.
 .
 This package contains the autogenerated documentation for Ruby 2.7.