Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.announce.security > #3462

[SECURITY] [DSA 4929-1] rails security update

Path csiph.com!newsfeed.xs4all.nl!newsfeed7.news.xs4all.nl!bofh.it!news.nic.it!robomod
From Moritz Muehlenhoff <jmm@debian.org>
Newsgroups linux.debian.announce.security
Subject [SECURITY] [DSA 4929-1] rails security update
Date Wed, 09 Jun 2021 23:20:02 +0200
Message-ID <CodMe-45I-7@gated-at.bofh.it> (permalink)
X-Mailbox-Line From debian-security-announce-request@lists.debian.org Wed Jun 9 21:11:49 2021
Old-Return-Path <jmm@seger.debian.org>
X-Amavis-Spam-Status No, score=-12.254 tagged_above=-10000 required=5.3 tests=[BAYES_00=-2, DIGITS_LETTERS=1, DKIMWL_WL_HIGH=-0.374, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FVGT_m_MULTI_ODD=0.02, LDO_WHITELIST=-5, PGPSIGNATURE=-5, RCVD_IN_DNSWL_LOW=-0.7] autolearn=ham autolearn_force=no
Old-Dkim-Signature v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=aN9HO8nLGDX1hduFU24g0yQ5yHfb/ZYG+3dLnV2up/0=; b=ct SxZY2+Ak4jhpns/ji6reg2WwHoOZASCrh814ackjTCQmktRjXWMOtd6KxK3jk3blRp0VPFgHSLQzf xBhbKMfKeFqUhjEGLhWz9GYIYgzWF6TOH1JGIO00K41+tLKNc347InCeFzW2pv80LrErW+SOY5gso D9WXjLXpaiSbeicXRgOa2c0XibHSBSKB0MRqTVHGX8J3LLinKgih2MY9hScEqmMNjUH8f8KMAnIAb JnnlXYQhYEfX9llaVA2kv+3iRWVemNFw4M3LmGPm/VQWduqftdqsUIZwGhis81DrDQcdQI9yUvTea 04btt4ThVNK3L044ZwP9eVP1tLKdDiDQ==;
MIME-Version 1.0
Content-Type text/plain; charset=us-ascii
Content-Disposition inline
User-Agent Mutt/1.10.1 (2018-07-13)
X-Debian PGP check passed for security officers
Priority urgent
Reply-To debian-security-announce-request@lists.debian.org
X-Mailing-List <debian-security-announce@lists.debian.org> archive/latest/3820
List-ID <debian-security-announce.lists.debian.org>
List-URL <http://lists.debian.org/debian-security-announce/>
List-Archive https://lists.debian.org/msgid-search/20210609211109.GB19453@seger.debian.org
Approved robomod@news.nic.it
Lines 46
Organization linux.* mail to news gateway
Sender robomod@news.nic.it
X-Original-Date Wed, 9 Jun 2021 21:11:09 +0000
X-Original-Message-ID <20210609211109.GB19453@seger.debian.org>
Xref csiph.com linux.debian.announce.security:3462

Show key headers only | View raw


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4929-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
June 09, 2021                         https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : rails
CVE ID         : CVE-2021-22880 CVE-2021-22885 CVE-2021-22904
Debian Bug     : 988214

Multiple security issues were discovered in the Rails web framework
which could result in denial of service.

For the stable distribution (buster), these problems have been fixed in
version 2:5.2.2.1+dfsg-1+deb10u3.

We recommend that you upgrade your rails packages.

For the detailed security status of rails please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/rails

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmDBLRkACgkQEMKTtsN8
TjarhQ//ehjd24UB/VzigZ4Pl2QlqG+UUX6oz2R3/bKFUV8Ql2mZ6nQv6lGFUxoU
8Slvjeo3spd9KgZ7vpQnjndlykaPzKbuV/q7eyO16nxUcUmhJZgI0CH3gD1v2kOQ
2Ah1BbPueQ9AS7EUxwDTBpnHkTceqh09P7gtkab3ZI2LsGfr4q7gXuxscU/HCtRE
kKLWRj4SvtVDEbM/RM4R3BxJrZphAZ0CJUqexoJgtcxZMCRAqaMxdr74dz1igjyY
0z7xzNs45lg/j4rHnrbWpfon4J83LcpO7GA412lmMvQA4ntXz1IkrnyB1E8OR5oI
wQDki3x+g2DqRCTyMheyuDlRiEk+esf5Sd+JqgtOLmFpyIaltAzUgwD1tdfsp2Uo
LsKR92rM/yJmoXQwD/L4JiGBwPx/NpXU9StkUXOo3d+ctK+u1wFO8ahnyU1wu4/G
72v36+QGtgQF1NXITQk4htZbMqQZF9JN+vQe6XucQsRfJVxW96JtTBsPAWQjGXWO
VWyD+YaS9B+/CCqGeVedXqjPT4r79xyCzBv//qQ2md1Yc4lo9J6D9UxNsEgcqT4d
M7yRXLPFOBzHzerm+3pvstBgbqOnv+Z57E28CGOb7/RCl7rZA6OAQHl4xpIHydt1
hhFNi9zAHF7XCQOqUIAM7gdXy/jRuhzcjsCh+9LA7GyXVvcqDM4=
=Tt64
-----END PGP SIGNATURE-----

Back to linux.debian.announce.security | Previous | Next | Find similar | Unroll thread


Thread

[SECURITY] [DSA 4929-1] rails security update Moritz Muehlenhoff <jmm@debian.org> - 2021-06-09 23:20 +0200

csiph-web