[Buildroot] [PATCH] package/ruby: security bump to version 2.4.6

Peter Korsgaard peter at korsgaard.com
Wed Apr 24 20:30:27 UTC 2019


>>>>> "Peter" == Peter Korsgaard <peter at korsgaard.com> writes:

 > Fixes the following security issues:
 > - CVE-2019-8320: Delete directory using symlink when decompressing tar
 > - CVE-2019-8321: Escape sequence injection vulnerability in verbose
 > - CVE-2019-8322: Escape sequence injection vulnerability in gem owner
 > - CVE-2019-8323: Escape sequence injection vulnerability in API response handling
 > - CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution
 > - CVE-2019-8325: Escape sequence injection vulnerability in errors

 > Signed-off-by: Peter Korsgaard <peter at korsgaard.com>

Committed to 2019.02.x, thanks.

-- 
Bye, Peter Korsgaard



More information about the buildroot mailing list