Ruby 2.4.2 Released Posted by nagachika on 14 Sep 2017 We are pleased to announce the release of Ruby 2.4.2. This release contains some security fixes. * CVE-2017-0898: Buffer underrun vulnerability in Kernel.sprintf * CVE-2017-10784: Escape sequence injection vulnerability in the Basic authentication of WEBrick * CVE-2017-14033: Buffer underrun vulnerability in OpenSSL ASN1 docod * CVE-2017-14064: Heap exposure in generating JSON * Multiple vulnerabilities in RubyGems * Update bundled libyaml to version 0.1.7. There are also many bug-fixes. See commit logs for more details. |
||
---|---|---|
.. | ||
patches | ||
ALTERNATIVES | ||
DEINSTALL | ||
DESCR | ||
distinfo | ||
hacks.mk | ||
INSTALL | ||
Makefile | ||
MESSAGE | ||
options.mk | ||
PLIST |