UbuntuUpdates.org

Package "ruby-webrick"

Name: ruby-webrick

Description:

HTTP server toolkit in Ruby

Latest version: 1.8.1-1ubuntu1.1
Release: plucky (25.04)
Level: updates
Repository: main
Homepage: https://github.com/ruby/webrick

Links


Download "ruby-webrick"


Other versions of "ruby-webrick" in Plucky

Repository Area Version
base main 1.8.1-1ubuntu1
security main 1.8.1-1ubuntu1.1

Changelog

Version: 1.8.1-1ubuntu1.1 2025-08-21 23:26:06 UTC

  ruby-webrick (1.8.1-1ubuntu1.1) plucky-security; urgency=medium

  * SECURITY UPDATE: read_header HTTP Request Smuggling Vulnerability
    - debian/patches/CVE-2025-6442-pre1.patch: fix ReDoS parse_header in
      lib/webrick/httputils.rb.
    - debian/patches/CVE-2025-6442-pre2.patch: fix ReDoS split_header_value
      in lib/webrick/httputils.rb.
    - debian/patches/CVE-2025-6442-pre3.patch: merge multiple cookie
      headers, preserving semantic correctness in
      lib/webrick/httprequest.rb, lib/webrick/httputils.rb,
      test/webrick/test_httprequest.rb.
    - debian/patches/CVE-2025-6442.patch: require CRLF line endings in
      request line and headers in lib/webrick/httprequest.rb,
      lib/webrick/httputils.rb, test/webrick/test_filehandler.rb,
      test/webrick/test_httprequest.rb.
    - CVE-2025-6442

 -- Marc Deslauriers <email address hidden> Thu, 14 Aug 2025 14:33:47 -0400

CVE-2025-6442 Ruby WEBrick read_header HTTP Request Smuggling Vulnerability. This vulnerability allows remote attackers to smuggle arbitrary HTTP requests on affec



About   -   Send Feedback to @ubuntu_updates