CVSROOT:        /cvs
Module name:    ports
Changes by:     [email protected]  2019/03/15 10:46:41

Modified files:
        lang/ruby/2.4  : Makefile distinfo 
        lang/ruby/2.4/pkg: PLIST-ri_docs 

Log message:
Use upstream patch to fix the following vulnerabilities in rubygems:

CVE-2019-8320: Delete directory using symlink when decompressing tar
CVE-2019-8321: Escape sequence injection vulnerability in verbose
CVE-2019-8322: Escape sequence injection vulnerability in gem owner
CVE-2019-8323: Escape sequence injection vulnerability in API response handling
CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution
CVE-2019-8325: Escape sequence injection vulnerability in errors

Reply via email to