Debian alert DLA-2561-1 (ruby-mechanize)
| From: | Utkarsh Gupta <utkarsh@debian.org> | |
| To: | debian-lts-announce@lists.debian.org | |
| Subject: | [SECURITY] [DLA 2561-1] ruby-mechanize security update | |
| Date: | Wed, 17 Feb 2021 02:08:15 +0530 | |
| Message-ID: | <CAPP0f94pPGYbT8J9qZaqUw8HR+g7XXjYPKjJ_G30hQ6Sj4e40Q@mail.gmail.com> |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 - ----------------------------------------------------------------------- Debian LTS Advisory DLA-2561-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Utkarsh Gupta February 17, 2021 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : ruby-mechanize Version : 2.7.5-1+deb9u1 CVE ID : CVE-2021-21289 Mechanize is an open-source Ruby library that makes automated web interaction easy. In Mechanize, from v2.0.0 until v2.7.7, there is a command injection vulnerability. Affected versions of Mechanize allow for OS commands to be injected using several classes' methods which implicitly use Ruby's Kernel#open method. For Debian 9 stretch, this problem has been fixed in version 2.7.5-1+deb9u1. We recommend that you upgrade your ruby-mechanize packages. For the detailed security status of ruby-mechanize please refer to its security tracker page at: https://security-tracker.debian.org/tracker/ruby-mechanize Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCAAdFiEEbJ0QSEqa5Mw4X3xxgj6WdgbDS5YFAmAsLMgACgkQgj6WdgbD S5ZT8g//VC2IQZxjdYdzBC+VOLZIRbfbLF7r6jsok62RmK5ZrvRr1fEKQ6VrDsQM Uf4F4MmmvlgFkqHjPODtFvhzDoM77JI/n6UhmYvxT5FJeS5dfEmCLEuRayS8H/v6 azj00hfGFqrW9FnkpPJfc/4tZosGhHEhPEHmHv7cNR7/ZcFBcgGxrCZseWv6c8Kp bu7mUUhQe2rWOjW4yRXRch+sNskCIfxaa4uD/lyJ17XNZapBhWF3Z/tlL3l2ZO+E OWwzOjYH9nZtfxK0TvJcjsSIKlMeCDjmDeGw0roVXQeGj2ywBYgfBh0DHhIBDdTp NsS7uxnSNMMcKiWs3PG1+GEXsZ7Sb7ZPjDQmhV1w2UX/uOnlFaeIeul5F7ZdRZG4 h4QZPww/MmcNRKkwwSZR+L7b7XZm4sWkaVdthqK+vg453NND4o6/2uc0DUrZEMg/ BKKwls8EPwYB1L5KK5TvkgG3V4JNDpg/UUL1H8lWXMhHzJnMokhwS5JI8peEfUDv YTzgA/XanMwse1uJXEPYFPuCfdzHJTqDSMoCPNRmKV45LBK/tq2oHTmC4vnz0Evp KxEB32E9WYvgHTntpkWZvMtdm2t0+qvrXxAXTXeAqmlErOYF8OndSRURK/GdIm4V VxKz8TVg3GcFWT6DLQv9hYdL33W4d7SJ5y6NjwR0+sdq1hkJUgs= =5Sy6 -----END PGP SIGNATURE-----
