UbuntuUpdates.org

Package "ruby2.7-doc"

Name: ruby2.7-doc

Description:

Documentation for Ruby 2.7

Latest version: 2.7.0-5ubuntu1.4
Release: focal (20.04)
Level: security
Repository: main
Head package: ruby2.7
Homepage: https://www.ruby-lang.org/

Links


Download "ruby2.7-doc"


Other versions of "ruby2.7-doc" in Focal

Repository Area Version
base main 2.7.0-5ubuntu1
updates main 2.7.0-5ubuntu1.4

Changelog

Version: 2.7.0-5ubuntu1.4 2021-04-20 19:07:20 UTC

  ruby2.7 (2.7.0-5ubuntu1.4) focal-security; urgency=medium

  * SECURITY UPDATE: XML round-trip vulnerability in REXML
    - debian/patches/CVE-2021-28965.patch: backport fixes from REXML
      3.2.3.1.
    - CVE-2021-28965

 -- Marc Deslauriers <email address hidden> Thu, 15 Apr 2021 10:38:03 -0400

Source diff to previous version

Version: 2.7.0-5ubuntu1.3 2021-03-18 18:07:08 UTC

  ruby2.7 (2.7.0-5ubuntu1.3) focal-security; urgency=medium

  * SECURITY UPDATE: sensitive info disclosure in BasicSocket#read_nonblock
    - debian/patches/CVE-2020-10933.patch: do not return uninitialized
      buffer in ext/socket/init.c.
    - CVE-2020-10933
  * SECURITY UPDATE: HTTP Request Smuggling attack in WEBrick
    - debian/patches/CVE-2020-25613.patch: make it more strict to interpret
      some headers in lib/webrick/httprequest.rb.
    - CVE-2020-25613

 -- Marc Deslauriers <email address hidden> Tue, 16 Mar 2021 10:56:44 -0400

CVE-2020-10933 An issue was discovered in Ruby 2.5.x through 2.5.7, 2.6.x through 2.6.5, and 2.7.0. If a victim calls BasicSocket#read_nonblock(requested_size, buff
CVE-2020-25613 An issue was discovered in Ruby through 2.5.8, 2.6.x through 2.6.6, and 2.7.x through 2.7.1. WEBrick, a simple HTTP server bundled with Ruby, had not



About   -   Send Feedback to @ubuntu_updates