mirror of
https://git.yoctoproject.org/poky
synced 2026-05-31 12:49:46 +00:00
ruby: Update to 2.4.4
The dot releases are maint only. 2.4.4 included: CVE-2017-17742: HTTP response splitting in WEBrick CVE-2018-6914: Unintentional file and directory creation with directory traversal in tempfile and tmpdir CVE-2018-8777: DoS by large request in WEBrick CVE-2018-8778: Buffer under-read in String#unpack CVE-2018-8779: Unintentional socket creation by poisoned NUL byte in UNIXServer and UNIXSocket CVE-2018-8780: Unintentional directory traversal by poisoned NUL byte in Dir (From OE-Core rev: ce12ff394281a42448d92109568db33739b2b542) (From OE-Core rev: 43721cc12ce782603ecdc0aa3a514bc6c8d4f97f) Signed-off-by: Armin Kuster <akuster808@gmail.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org> [Fixup for Morty context] Signed-off-by: Armin Kuster <akuster808@gmail.com> Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
This commit is contained in:
committed by
Richard Purdie
parent
3be01630d8
commit
e31e85d869
@@ -8,8 +8,8 @@ SRC_URI += " \
|
||||
file://ruby-CVE-2017-9229.patch \
|
||||
"
|
||||
|
||||
SRC_URI[md5sum] = "a00e0d49b454f4c0e528e7852d642925"
|
||||
SRC_URI[sha256sum] = "fd0375582c92045aa7d31854e724471fb469e11a4b08ff334d39052ccaaa3a98"
|
||||
SRC_URI[md5sum] = "d50e00ccc1c9cf450f837b92d3ed3e88"
|
||||
SRC_URI[sha256sum] = "254f1c1a79e4cc814d1e7320bc5bdd995dc57e08727d30a767664619a9c8ae5a"
|
||||
|
||||
# it's unknown to configure script, but then passed to extconf.rb
|
||||
# maybe it's not really needed as we're hardcoding the result with
|
||||
Reference in New Issue
Block a user