Subject: CVS commit: [pkgsrc-2022Q4] pkgsrc/www/ruby-rack
From: S.P.Zeidler
Date: 2023-03-04 15:35:53
Message id: 20230304143553.50F35FA90@cvs.NetBSD.org

Log Message:
Pullup ticket #6738 - requested by taca
www/ruby-rack: security update

Revisions pulled up:
pkgsrc/www/ruby-rack/Makefile		by patch
pkgsrc/www/ruby-rack/distinfo		by patch

-------------------------------------------------------------------

   Log Message:
   www/ruby-rack2: update to 2.2.6.2

   2.2.6 (2022-01-17)

   * Extend Rack::MethodOverride to handle QueryParser::ParamsTooDeepError
     error.  (#2011, @byroot)

   2.2.6.1 (2022-01-17)

   * [CVE-2022-44571] Fix ReDoS vulnerability in multipart parser
   * [CVE-2022-44570] Fix ReDoS in Rack::Utils.get_byte_ranges
   * [CVE-2022-44572] Forbid control characters in attributes (also ReDoS)

   2.2.6.2 (2022-01-17)

   * [CVE-2022-44570] Fix ReDoS in Rack::Utils.get_byte_ranges

Files:
RevisionActionfile
1.31.4.1modifypkgsrc/www/ruby-rack/Makefile
1.29.4.1modifypkgsrc/www/ruby-rack/distinfo