Format: 1.8 Date: Thu, 06 Jan 2022 09:34:12 -0300 Source: ruby2.7 Binary: libruby2.7 ruby2.7 ruby2.7-dev Architecture: s390x Version: 2.7.0-5ubuntu1.6 Distribution: focal Urgency: medium Maintainer: Launchpad Build Daemon Changed-By: Leonidas Da Silva Barbosa Description: libruby2.7 - Libraries necessary to run Ruby 2.7 ruby2.7 - Interpreter of object-oriented scripting language Ruby ruby2.7-dev - Header files for compiling extension modules for the Ruby 2.7 Changes: ruby2.7 (2.7.0-5ubuntu1.6) focal-security; urgency=medium . * SECURITY UPDATE: Buffer overrun - debian/patches/CVE-2021-41816.patch: fix integer overflow making sure use of the check in rb_alloc_tmp_buffer2 in ext/cgi/escape/escape.c. - CVE-2021-41816 * SECURITY UPDATE: ReDoS vulnerability - debian/patches/CVE-2021-41817-*.patch: add length limit option for methods that parses date strings and mimic prev behaviour in ext/date/date_core.c, test/date/test_date_parse.rb. - CVE-2021-41817 * SECURITY UPDATE: Mishandles sec prefixes in cookie names - debian/patches/CVE-2021-41819.patch: when parsing cookies, only decode the values in lib/cgi/cookie.rb, test/cgi/test_cgi_cookie.rb. - CVE-2021-41819 Checksums-Sha1: bb721a01b1fb443055f973d6d25dd08bb1b6a6bb 6665860 libruby2.7-dbgsym_2.7.0-5ubuntu1.6_s390x.ddeb db6a8dca6c239db8341c5bf4c5560cb6399d4356 3379956 libruby2.7_2.7.0-5ubuntu1.6_s390x.deb 5e591390a15318285276ff7ea353a903b9b226d2 5232 ruby2.7-dbgsym_2.7.0-5ubuntu1.6_s390x.ddeb 8c0cc39d5571dc9c6a937a2caaa71a5789e716be 183624 ruby2.7-dev_2.7.0-5ubuntu1.6_s390x.deb 0fa1ee3f87250e1398316d8740084cd064d3cefd 7392 ruby2.7_2.7.0-5ubuntu1.6_s390x.buildinfo f42d3736d6ff25d3025b38e3e9092bf66329a0ed 95440 ruby2.7_2.7.0-5ubuntu1.6_s390x.deb Checksums-Sha256: cbe9036c7d7ce1a2e04a3ee0c851959b471ba6d805cf87194b394676a8efdce5 6665860 libruby2.7-dbgsym_2.7.0-5ubuntu1.6_s390x.ddeb af4df9bc1138a3214d397ffde856f9c85575b57fb4aede4754ff447653dc2da8 3379956 libruby2.7_2.7.0-5ubuntu1.6_s390x.deb e321bcf1097730c3da6fbfa1c8f25ee8462ce3943a81fd24009aa4152bd7154c 5232 ruby2.7-dbgsym_2.7.0-5ubuntu1.6_s390x.ddeb 09c2a7d095355ba86530c8b13fd6d014ef566eedc119d74ef0ede852c1b27bae 183624 ruby2.7-dev_2.7.0-5ubuntu1.6_s390x.deb b6ffa71168a04841e3ec088b80de23844b4b4ce7e0757540ca6a473743f6373e 7392 ruby2.7_2.7.0-5ubuntu1.6_s390x.buildinfo 3b40a4a462444e22ac5cdb9e430a4f48c23cec24b8122ff124761f02ba28742c 95440 ruby2.7_2.7.0-5ubuntu1.6_s390x.deb Files: 06bd533b7eb51d095226c46294c273e6 6665860 debug optional libruby2.7-dbgsym_2.7.0-5ubuntu1.6_s390x.ddeb b7eac7a0eed0c9ab9d79e469a59a1d18 3379956 libs optional libruby2.7_2.7.0-5ubuntu1.6_s390x.deb cc52be390d6675f3460e44b37e149250 5232 debug optional ruby2.7-dbgsym_2.7.0-5ubuntu1.6_s390x.ddeb 18787188d3d8aa3f27fe6be8bac20232 183624 ruby optional ruby2.7-dev_2.7.0-5ubuntu1.6_s390x.deb 73393dafbce9e59d21e1d28f6f57c556 7392 ruby optional ruby2.7_2.7.0-5ubuntu1.6_s390x.buildinfo e7036460fc0de692d5fa89cc87e4f9de 95440 ruby optional ruby2.7_2.7.0-5ubuntu1.6_s390x.deb Original-Maintainer: Debian Ruby Team