Zum Inhalt springen.
Sympa Menü

it-securitynotifies - [IT-SecNots] [SECURITY] [DSA 4929-1] rails security update

it-securitynotifies AT lists.piratenpartei.de

Betreff: Sicherheitsankündigungen

Listenarchiv

[IT-SecNots] [SECURITY] [DSA 4929-1] rails security update


Chronologisch Thread 
  • From: Moritz Muehlenhoff <jmm AT debian.org>
  • To: debian-security-announce AT lists.debian.org
  • Subject: [IT-SecNots] [SECURITY] [DSA 4929-1] rails security update
  • Date: Wed, 9 Jun 2021 21:11:09 +0000
  • Authentication-results: mail02.piratenpartei.de; dkim=none; spf=none (mail02.piratenpartei.de: domain of "bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org" has no SPF policy when checking 82.195.75.100) smtp.mailfrom="bounce-debian-security-announce=it-securitynotifies=lists.piratenpartei.de AT lists.debian.org"; dmarc=none
  • List-archive: https://lists.debian.org/msgid-search/20210609211109.GB19453 AT seger.debian.org
  • List-id: <debian-security-announce.lists.debian.org>
  • List-url: <http://lists.debian.org/debian-security-announce/>
  • Old-dkim-signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=debian.org; s=smtpauto.seger; h=Content-Type:MIME-Version:Message-ID:Subject:To:From: Date:Reply-To:Cc:Content-Transfer-Encoding:Content-ID:Content-Description: In-Reply-To:References; bh=aN9HO8nLGDX1hduFU24g0yQ5yHfb/ZYG+3dLnV2up/0=; b=ct SxZY2+Ak4jhpns/ji6reg2WwHoOZASCrh814ackjTCQmktRjXWMOtd6KxK3jk3blRp0VPFgHSLQzf xBhbKMfKeFqUhjEGLhWz9GYIYgzWF6TOH1JGIO00K41+tLKNc347InCeFzW2pv80LrErW+SOY5gso D9WXjLXpaiSbeicXRgOa2c0XibHSBSKB0MRqTVHGX8J3LLinKgih2MY9hScEqmMNjUH8f8KMAnIAb JnnlXYQhYEfX9llaVA2kv+3iRWVemNFw4M3LmGPm/VQWduqftdqsUIZwGhis81DrDQcdQI9yUvTea 04btt4ThVNK3L044ZwP9eVP1tLKdDiDQ==;
  • Old-return-path: <jmm AT seger.debian.org>
  • Priority: urgent
  • Resent-date: Wed, 9 Jun 2021 21:11:49 +0000 (UTC)
  • Resent-from: debian-security-announce AT lists.debian.org
  • Resent-message-id: <cd9sIgNWSVH.A.r4C.V6SwgB@bendel>
  • Resent-sender: debian-security-announce-request AT lists.debian.org

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-4929-1 security AT debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
June 09, 2021 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : rails
CVE ID : CVE-2021-22880 CVE-2021-22885 CVE-2021-22904
Debian Bug : 988214

Multiple security issues were discovered in the Rails web framework
which could result in denial of service.

For the stable distribution (buster), these problems have been fixed in
version 2:5.2.2.1+dfsg-1+deb10u3.

We recommend that you upgrade your rails packages.

For the detailed security status of rails please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/rails

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce AT lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmDBLRkACgkQEMKTtsN8
TjarhQ//ehjd24UB/VzigZ4Pl2QlqG+UUX6oz2R3/bKFUV8Ql2mZ6nQv6lGFUxoU
8Slvjeo3spd9KgZ7vpQnjndlykaPzKbuV/q7eyO16nxUcUmhJZgI0CH3gD1v2kOQ
2Ah1BbPueQ9AS7EUxwDTBpnHkTceqh09P7gtkab3ZI2LsGfr4q7gXuxscU/HCtRE
kKLWRj4SvtVDEbM/RM4R3BxJrZphAZ0CJUqexoJgtcxZMCRAqaMxdr74dz1igjyY
0z7xzNs45lg/j4rHnrbWpfon4J83LcpO7GA412lmMvQA4ntXz1IkrnyB1E8OR5oI
wQDki3x+g2DqRCTyMheyuDlRiEk+esf5Sd+JqgtOLmFpyIaltAzUgwD1tdfsp2Uo
LsKR92rM/yJmoXQwD/L4JiGBwPx/NpXU9StkUXOo3d+ctK+u1wFO8ahnyU1wu4/G
72v36+QGtgQF1NXITQk4htZbMqQZF9JN+vQe6XucQsRfJVxW96JtTBsPAWQjGXWO
VWyD+YaS9B+/CCqGeVedXqjPT4r79xyCzBv//qQ2md1Yc4lo9J6D9UxNsEgcqT4d
M7yRXLPFOBzHzerm+3pvstBgbqOnv+Z57E28CGOb7/RCl7rZA6OAQHl4xpIHydt1
hhFNi9zAHF7XCQOqUIAM7gdXy/jRuhzcjsCh+9LA7GyXVvcqDM4=
=Tt64
-----END PGP SIGNATURE-----



  • [IT-SecNots] [SECURITY] [DSA 4929-1] rails security update, Moritz Muehlenhoff, 09.06.2021

Archiv bereitgestellt durch MHonArc 2.6.24.

Seitenanfang