UbuntuUpdates.org

Package "ruby-nokogiri"

Name: ruby-nokogiri

Description:

HTML, XML, SAX, and Reader parser for Ruby

Latest version: 1.8.2-1ubuntu0.1
Release: bionic (18.04)
Level: security
Repository: universe
Homepage: http://nokogiri.org

Links


Download "ruby-nokogiri"


Other versions of "ruby-nokogiri" in Bionic

Repository Area Version
base universe 1.8.2-1build1
updates universe 1.8.2-1ubuntu0.1

Changelog

Version: 1.8.2-1ubuntu0.1 2019-11-05 15:07:03 UTC

  ruby-nokogiri (1.8.2-1ubuntu0.1) bionic-security; urgency=medium

  * SECURITY UPDATE: Command injection vulnerability.
    - debian/patches/CVE-2019-5477.patch: prefer File.open to Kernel.open.
    - CVE-2019-5477

 -- Eduardo Barretto <email address hidden> Mon, 04 Nov 2019 11:05:18 -0300

CVE-2019-5477 A command injection vulnerability in Nokogiri v1.10.3 and earlier allows commands to be executed in a subprocess via Ruby's `Kernel.open` method. Pro



About   -   Send Feedback to @ubuntu_updates