Skip to content
GitLab
Explore
Sign in
Register
Commits on Source (4)
jruby 1.5.6-5 vulnerable to CVE-2018-1000074
· 4fe929ed
Chris Lamb
authored
Apr 02, 2018
4fe929ed
Triage jruby for LTS
· c5c89f2c
Chris Lamb
authored
Apr 02, 2018
c5c89f2c
Triage rubygems for LTS
· 759dc058
Chris Lamb
authored
Apr 02, 2018
759dc058
data/dla-needed.txt: Add note for ruby 1.9.1.
· 8cb9f6ab
Chris Lamb
authored
Apr 02, 2018
8cb9f6ab
Show whitespace changes
Inline
Side-by-side
data/CVE/list
View file @
8cb9f6ab
...
...
@@ -4986,7 +4986,7 @@ CVE-2018-1000074 (RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3
- ruby2.1 <removed>
- ruby1.9.1 <removed>
- rubygems <removed>
- jruby
<unfixed>
- jruby
1.5.6-5
NOTE: https://github.com/rubygems/rubygems/commit/254e3d0ee873c008c0b74e8b8abcbdab4caa0a6d
NOTE: https://www.ruby-lang.org/en/news/2018/02/17/multiple-vulnerabilities-in-rubygems/
CVE-2018-1000073 (RubyGems version Ruby 2.2 series: 2.2.9 and earlier, Ruby 2.3 series: ...)
data/dla-needed.txt
View file @
8cb9f6ab
...
...
@@ -43,6 +43,8 @@ ipython
NOTE: with untrusted content and upgrade to Jessie. Please double-check all
NOTE: this.
--
jruby
--
krb5
NOTE: lts-do-not-call
NOTE: Details not public. Yet. See https://lists.debian.org/msgid-search/20180208212643.GB7792@pisco.westfalen.local
...
...
@@ -105,6 +107,9 @@ qemu-kvm
ruby-rack-protection
--
ruby1.9.1 (Santiago R.R.)
NOTE: 20180402: Also vulnerable to CVE-2018-1000074. (lamby)
--
rubygems
--
sam2p (Markus Koschany)
--
...
...