From $URL: WEBrick have had a cross-site scripting vulnerability that allows an attacker to inject arbitrary script or HTML via a crafted URI. This does not affect user agents that strictly implement HTTP/1.1, however, some user agents do not. The affected versions are: * Ruby 1.8.6-p399 or any prior releases. * Ruby 1.8.7-p299 or any prior releases. * Ruby 1.9.1-p429 or any prior releases. * Ruby 1.9.2 RC2 or any prior releases. * Development versions of Ruby 1.9 (1.9.3dev). We recommend you to upgrade your ruby to the newest patch level releases.
1.8.6 → backport 1.8.7 → update to _p302 1.9.2_rc2 → backport (~arch + p.masked)
Arches, please test and mark stable: =dev-lang/ruby-1.8.7_p302 Target keywords : "alpha amd64 arm hppa ia64 ppc ppc64 s390 sh sparc x86"
Stable for HPPA PPC.
amd64 done
x86 stable
dev-lang/jruby is also affected; I've added the 1.5.2 version to the tree, which solves it, and should be ready to go stable for x86/amd64. The problem is with ppc that still got an ancient jruby version that is not even compatible with the ruby-ng system... I guess they might want to remove the 1.3.1-r1 ebuild entirely for now.
arm stable
alpha/ia64/s390/sh/sparc stable
Fixed in dev-lang/ruby-enterprise-1.8.7.2010.02-r1 (~arch only).
ppc64 done
PPC was done by jer, too. Removing from CC. GLSA vote: NO
No, too. Closing noglsa.