Path to this page:
Subject: CVS commit: [pkgsrc-2022Q4] pkgsrc/www/ruby-rack
From: S.P.Zeidler
Date: 2023-03-04 15:35:53
Message id: 20230304143553.50F35FA90@cvs.NetBSD.org
Log Message:
Pullup ticket #6738 - requested by taca
www/ruby-rack: security update
Revisions pulled up:
pkgsrc/www/ruby-rack/Makefile by patch
pkgsrc/www/ruby-rack/distinfo by patch
-------------------------------------------------------------------
Log Message:
www/ruby-rack2: update to 2.2.6.2
2.2.6 (2022-01-17)
* Extend Rack::MethodOverride to handle QueryParser::ParamsTooDeepError
error. (#2011, @byroot)
2.2.6.1 (2022-01-17)
* [CVE-2022-44571] Fix ReDoS vulnerability in multipart parser
* [CVE-2022-44570] Fix ReDoS in Rack::Utils.get_byte_ranges
* [CVE-2022-44572] Forbid control characters in attributes (also ReDoS)
2.2.6.2 (2022-01-17)
* [CVE-2022-44570] Fix ReDoS in Rack::Utils.get_byte_ranges
Files: