Package        : ruby-sprockets
Version        : 2.12.3-1+deb8u1
CVE IDs        : CVE-2018-3760 
Debian Bug     : #901913

It was discovered that there was a discovered a path traversal flaw
in ruby-sprockets, a Rack-based asset packaging system. A remote
attacker could take advantage of this flaw to read arbitrary files
outside an application's root directory via "file://" requests.

For Debian 8 "Jessie", this issue has been fixed in ruby-sprockets version
2.12.3-1+deb8u1.

We recommend that you upgrade your ruby-sprockets packages.


Regards,

- -- 
      ,''`.
     : :'  :     Chris Lamb
     `. `'`      lamby@debian.org / chris-lamb.co.uk
       `-

Debian LTS: DLA-1419-1: ruby-sprockets security update

July 12, 2018
It was discovered that there was a discovered a path traversal flaw in ruby-sprockets, a Rack-based asset packaging system

Summary

We recommend that you upgrade your ruby-sprockets packages.


Regards,

- --
,''`.
: :' : Chris Lamb
`. `'` lamby@debian.org / chris-lamb.co.uk
`-



Severity
Package : ruby-sprockets
Version : 2.12.3-1+deb8u1
Debian Bug : #901913

Related News