CVSROOT: /cvs
Module name: ports
Changes by: [email protected] 2019/03/15 10:46:41
Modified files:
lang/ruby/2.4 : Makefile distinfo
lang/ruby/2.4/pkg: PLIST-ri_docs
Log message:
Use upstream patch to fix the following vulnerabilities in rubygems:
CVE-2019-8320: Delete directory using symlink when decompressing tar
CVE-2019-8321: Escape sequence injection vulnerability in verbose
CVE-2019-8322: Escape sequence injection vulnerability in gem owner
CVE-2019-8323: Escape sequence injection vulnerability in API response handling
CVE-2019-8324: Installing a malicious gem may lead to arbitrary code execution
CVE-2019-8325: Escape sequence injection vulnerability in errors