]> code.ossystems Code Review - openembedded-core.git/commit
ruby : update to 3.0.3
authorLee Chee Yang <chee.yang.lee@intel.com>
Mon, 28 Feb 2022 03:38:37 +0000 (11:38 +0800)
committerAnuj Mittal <anuj.mittal@intel.com>
Mon, 7 Mar 2022 07:39:05 +0000 (15:39 +0800)
commitedb6df08cb47a39918d28c709675d995c9e10031
tree1da0f0797c9535c53ab2456ac70cc526f221a5f9
parent7b5723ae41b7fcdc73a24f04ec0cda4fba8f8622
ruby : update to 3.0.3

Do not tweak a file that is no longer installed.

Ruby 3.0.3 includes security fixes.
CVE-2021-41817: Regular Expression Denial of Service Vulnerability of Date Parsing Methods
CVE-2021-41816: Buffer Overrun in CGI.escape_html
CVE-2021-41819: Cookie Prefix Spoofing in CGI::Cookie.parse

Ruby 3.0.2 release includes security fixes.
CVE-2021-31810: Trusting FTP PASV responses vulnerability in Net::FTP
CVE-2021-32066: A StartTLS stripping vulnerability in Net::IMAP
CVE-2021-31799: A command injection vulnerability in RDoc

Signed-off-by: Lee Chee Yang <chee.yang.lee@intel.com>
Signed-off-by: Anuj Mittal <anuj.mittal@intel.com>
meta/recipes-devtools/ruby/ruby/CVE-2021-31799.patch [deleted file]
meta/recipes-devtools/ruby/ruby/CVE-2021-31810.patch [deleted file]
meta/recipes-devtools/ruby/ruby/CVE-2021-32066.patch [deleted file]
meta/recipes-devtools/ruby/ruby_3.0.3.bb [moved from meta/recipes-devtools/ruby/ruby_3.0.1.bb with 90% similarity]