Debian LTS: DLA-1419-1: ruby-sprockets security update
Summary
We recommend that you upgrade your ruby-sprockets packages.
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-
Package : ruby-sprockets Version : 2.12.3-1+deb8u1 CVE IDs : CVE-2018-3760 Debian Bug : #901913 It was discovered that there was a discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system. A remote attacker could take advantage of this flaw to read arbitrary files outside an application's root directory via "file://" requests. For Debian 8 "Jessie", this issue has been fixed in ruby-sprockets version 2.12.3-1+deb8u1. We recommend that you upgrade your ruby-sprockets packages. Regards, - -- ,''`. : :' : Chris Lamb `. `'` lamby@debian.org / chris-lamb.co.uk `-
We recommend that you upgrade your ruby-sprockets packages.
Regards,
- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-