Package "ruby2.7-dev"

Name: ruby2.7-dev


Header files for compiling extension modules for the Ruby 2.7

Latest version: 2.7.2-4ubuntu1.2
Release: hirsute (21.04)
Level: updates
Repository: main
Head package: ruby2.7
Homepage: https://www.ruby-lang.org/


Download "ruby2.7-dev"

Other versions of "ruby2.7-dev" in Hirsute

Repository Area Version
base main 2.7.2-4ubuntu1
security main 2.7.2-4ubuntu1.2


Version: 2.7.2-4ubuntu1.2 2021-07-21 17:06:24 UTC

  ruby2.7 (2.7.2-4ubuntu1.2) hirsute-security; urgency=medium

  * SECURITY UPDATE: Command injection vulnerability in RDoc
    - debian/patches/CVE-2021-31799.patch: fix replace open for File.open
      in lib/rdoc/rdoc.rb, test/rdoc/test_rdoc_rdoc.rb.
    - CVE-2021-31799
  * SECURITY UPDATE: Information leak
    - debian/patches/CVE-2021-31810.patch: ignore IP address in PASV
      responses by default and add new option use_pasv_ip in lib/net/ftp.rb,
    - CVE-2021-31810
  * SECURITY UPDATE: Stripping vulnerability
    - debian/patches/CVE-2021-32066.patch: fix raising an exception
      when a unknow response error happens in
      lib/net/imap.rb, test/net/imap/test_imap.rb.
    - CVE-2021-32066

 -- Leonidas Da Silva Barbosa <email address hidden> Fri, 16 Jul 2021 09:11:26 -0300

Source diff to previous version
CVE-2021-31799 A command injection vulnerability in RDoc
CVE-2021-31810 An issue was discovered in Ruby through 2.6.7, 2.7.x through 2.7.3, and 3.x through 3.0.1. A malicious FTP server can use the PASV response to trick
CVE-2021-32066 A StartTLS stripping vulnerability in Net::IMAP

Version: 2.7.2-4ubuntu1.1 2021-04-26 14:06:25 UTC

  ruby2.7 (2.7.2-4ubuntu1.1) hirsute-security; urgency=medium

  * SECURITY UPDATE: XML round-trip vulnerability in REXML
    - debian/patches/CVE-2021-28965.patch: backport fixes from REXML
    - CVE-2021-28965

 -- Marc Deslauriers <email address hidden> Thu, 22 Apr 2021 14:27:19 -0400

CVE-2021-28965 The REXML gem before 3.2.5 in Ruby before 2.6.7, 2.7.x before 2.7.3, and 3.x before 3.0.1 does not properly address XML round-trip issues. An incorre

About   -   Send Feedback to @ubuntu_updates