Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Fedora 31: rubygem-rack Update FEDORA-2020-57fc0d0156 Critical Session Risk

fedora
Calendar Grey January 18, 2020
Dist Fedora Esm H88
A new rubygem-rack version 2.0.8 has been released to fix session hijacking vulnerabilities. Users are urged to update for enhanced session protection
Update to Rack 2.0.8.

Summary

Rack provides a minimal, modular and adaptable interface for developing

web applications in Ruby. By wrapping HTTP requests and responses in

the simplest way possible, it unifies and distills the API for web

servers, web frameworks, and software in between (the so-called

middleware) into a single method call.

Update to Rack 2.0.8.

* Thu Jan 9 2020 Gerd Pokorra - 1:2.0.8-1

- Update to Rack 2.0.8.

- Change the source URL

[ 1 ] Bug #1789101 - CVE-2019-16782 rubygem-rack: hijack sessions by using timing attacks targeting the session id [fedora-all]

https://bugzilla.redhat.com/show_bug.cgi?id=1789101

su -c 'dnf upgrade --advisory FEDORA-2020-57fc0d0156' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
critical
Lowest
Low
Medium
High
Critical

Product: Fedora 31
Version: 2.0.8
Release: 1.fc31
Summary: A modular Ruby webserver interface

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here