Path to this page:
Subject: CVS commit: pkgsrc
From: Takahiro Kambe
Date: 2021-02-11 15:23:42
Message id: 20210211142342.EF549FA95@cvs.NetBSD.org
Log Message:
www/rails52: update to 5.2.4.5
## Rails 5.2.4.5 (February 10, 2021) ##
* Fix possible DoS vector in PostgreSQL money type
Carefully crafted input can cause a DoS via the regular expressions used
for validating the money format in the PostgreSQL adapter. This patch
fixes the regexp.
Thanks to @dee-see from Hackerone for this patch!
[CVE-2021-22880]
*Aaron Patterson*
Files: