Summary: | <dev-ruby/rack-2.1.4: Directory Traversal Vulnerability (CVE-2020-8161) | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | RESOLVED FIXED | ||
Severity: | trivial | CC: | ruby |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
URL: | https://groups.google.com/forum/?oldui=1#!topic/rubyonrails-security/IOO1vNZTzPA | ||
Whiteboard: | C4 [noglsa] | ||
Package list: | Runtime testing required: | --- | |
Bug Depends on: | 730786 | ||
Bug Blocks: |
Description
John Helmert III
2020-07-02 23:34:13 UTC
As far as I can tell slot 2.1 and 2.2 have only fixed versions in the repository, but slot 1.6 and 2.0 are vulnerable. Stabling has been superseded by bug 730786 Resetting sanity check; keywords are not fully specified and arches are not CC-ed. Unable to check for sanity:
> no match for package: dev-ruby/rack-2.2.2
Tree is clean, all done! |