| Summary: | dev-ruby/tzinfo:1: arbitrary code execution | ||
|---|---|---|---|
| Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
| Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
| Status: | RESOLVED INVALID | ||
| Severity: | normal | CC: | ruby |
| Priority: | Normal | ||
| Version: | unspecified | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | https://github.com/tzinfo/tzinfo/security/advisories/GHSA-5cm2-9h8c-rvfx | ||
| Whiteboard: | B2 [ebuild] | ||
| Package list: | Runtime testing required: | --- | |
|
Description
John Helmert III
2022-07-22 11:51:28 UTC
"as well as those prior to 1.2.10 when used with the Ruby data source tzinfo-data" We don't package tzinfo-data, since we depend on sys-libs/timezone-data instead for better system-wide consistency. In any case 1.2.10 added. Thanks! |