Change logs for ruby-rack source package in Noble

  • ruby-rack (2.2.7-1ubuntu0.1) noble-security; urgency=medium
    
      * SECURITY UPDATE: DoS via crafted content type headers
        - debian/patches/CVE-2024-25126.patch: avoid 2nd degree polynomial
          regexp in MediaType in lib/rack/media_type.rb.
        - CVE-2024-25126
      * SECURITY UPDATE: DoS via crafted Range headers
        - debian/patches/CVE-2024-26141.patch: return an empty array when
          ranges are too large in lib/rack/utils.rb, test/spec_utils.rb.
        - CVE-2024-26141
      * SECURITY UPDATE: Dos via crafted headers
        - debian/patches/CVE-2024-26146.patch: fix ReDoS in header parsing in
          lib/rack/utils.rb.
        - CVE-2024-26146
    
     -- Marc Deslauriers <email address hidden>  Fri, 14 Jun 2024 13:15:36 -0400
  • ruby-rack (2.2.7-1) unstable; urgency=medium
    
      * Team Upload
      * New upstream version 2.2.7
    
     -- Pirate Praveen <email address hidden>  Mon, 10 Jul 2023 20:02:41 +0530
  • ruby-rack (2.2.4-3) unstable; urgency=high
    
      * Team upload
      * Fix test failures (Closes:  #1030442)
      * Fix CVE-2022-44570 CVE-2022-44571 CVE-2022-44572 (Closes:  #1029832)
      * Add Breaks for ruby-sinatra
    
     -- Sruthi Chandran <email address hidden>  Thu, 09 Feb 2023 11:47:17 +0100