|
|
Subscribe / Log in / New account

Fedora alert FEDORA-2017-c22a8af4e9 (rubygem-rack-cors)

From:  updates@fedoraproject.org
To:  package-announce@lists.fedoraproject.org
Subject:  [SECURITY] Fedora 25 Update: rubygem-rack-cors-0.4.1-1.fc25
Date:  Tue, 25 Jul 2017 00:29:40 +0000 (UTC)
Message-ID:  <20170725002940.343856057136@bastion01.phx2.fedoraproject.org>

-------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2017-c22a8af4e9 2017-07-24 17:29:46.084692 -------------------------------------------------------------------------------- Name : rubygem-rack-cors Product : Fedora 25 Version : 0.4.1 Release : 1.fc25 URL : https://github.com/cyu/rack-cors Summary : Middleware for enabling Cross-Origin Resource Sharing in Rack apps Description : Middleware that will make Rack-based apps CORS compatible. Read more here: http://blog.sourcebender.com/2010/06/09/introducin-rack-c... Fork the project here: https://github.com/cyu/rack-cors. -------------------------------------------------------------------------------- Update Information: Security fix for CVE-2017-11173, new upstream version -------------------------------------------------------------------------------- References: [ 1 ] Bug #1470689 - CVE-2017-11173 rubygem-rack-cors: Missing anchor in generated regex in rack/cors.rb#L256 may permit forged malicious requests [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1470689 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade rubygem-rack-cors' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgr... All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list -- package-announce@lists.fedoraproject.org To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds