Debian Package Tracker
Register | Log in
Subscribe

ruby-icalendar

ruby implementation of the iCalendar specification (RFC-5545)

Choose email to subscribe with

general
  • source: ruby-icalendar (main)
  • version: 2.8.0-1
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Pirate Praveen [DMD]
  • arch: all
  • std-ver: 4.6.1
  • VCS: Git (Browse)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2.4.1-2
  • oldstable: 2.8.0-1
versioned links
  • 2.4.1-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.8.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-icalendar
package is gone
This package is not in any development repository. This probably means that the package has been removed (or has been renamed). Thus the information here is of little interest ... the package is going to disappear unless someone takes it over and reintroduces it.
action needed
Debci reports failed tests high
  • unstable: fail (log)
    The tests ran in 0:00:17
    Last run: 2025-04-16T21:03:52.000Z
    Previous status: unknown

  • testing: pass (log)
    The tests ran in 0:00:30
    Last run: 2025-04-05T14:50:54.000Z
    Previous status: unknown

  • stable: fail (log)
    The tests ran in 0:00:29
    Last run: 2025-08-10T18:37:23.000Z
    Previous status: unknown

Created: 2025-04-16 Last update: 2026-03-29 00:04
1 security issue in bullseye high

There is 1 open security issue in bullseye.

1 important issue:
  • CVE-2026-33635: iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in version 2.0.0 and prior to version 2.12.2, .ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. `Icalendar::Values::Uri` falls back to the raw input string when `URI.parse` fails and later serializes it with `value.to_s` without removing or escaping `\r` or `\n` characters. That value is embedded directly into the final ICS line by the normal serializer, so a payload containing CRLF can terminate the original property and create a new ICS property or component. (It looks like you can inject via url, source, image, organizer, attach, attendee, conference, tzurl because of this). Applications that generate `.ics` files from partially untrusted metadata are impacted. As a result, downstream calendar clients or importers may process attacker-supplied content as if it were legitimate event data, such as added attendees, modified URLs, alarms, or other calendar fields. Version 2.12.2 contains a patch for the issue.
Created: 2026-03-28 Last update: 2026-03-28 14:46
1 security issue in bookworm high

There is 1 open security issue in bookworm.

1 important issue:
  • CVE-2026-33635: iCalendar is a Ruby library for dealing with iCalendar files in the iCalendar format defined by RFC-5545. Starting in version 2.0.0 and prior to version 2.12.2, .ics serialization does not properly sanitize URI property values, enabling ICS injection through attacker-controlled input, adding arbitrary calendar lines to the output. `Icalendar::Values::Uri` falls back to the raw input string when `URI.parse` fails and later serializes it with `value.to_s` without removing or escaping `\r` or `\n` characters. That value is embedded directly into the final ICS line by the normal serializer, so a payload containing CRLF can terminate the original property and create a new ICS property or component. (It looks like you can inject via url, source, image, organizer, attach, attendee, conference, tzurl because of this). Applications that generate `.ics` files from partially untrusted metadata are impacted. As a result, downstream calendar clients or importers may process attacker-supplied content as if it were legitimate event data, such as added attendees, modified URLs, alarms, or other calendar fields. Version 2.12.2 contains a patch for the issue.
Created: 2026-03-28 Last update: 2026-03-28 14:46
news
[rss feed]
  • [2025-04-17] ruby-icalendar REMOVED from testing (Debian testing watch)
  • [2025-04-16] Removed 2.10.3-1 from unstable (Debian FTP Masters)
  • [2024-11-16] ruby-icalendar 2.10.3-1 MIGRATED to testing (Debian testing watch)
  • [2024-11-13] Accepted ruby-icalendar 2.10.3-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2023-11-05] ruby-icalendar 2.10.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-11-02] Accepted ruby-icalendar 2.10.0-1 (source) into unstable (Cédric Boutillier)
  • [2022-07-22] ruby-icalendar 2.8.0-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-18] Accepted ruby-icalendar 2.8.0-1 (source) into unstable (Cédric Boutillier)
  • [2022-01-29] ruby-icalendar 2.7.1-1 MIGRATED to testing (Debian testing watch)
  • [2022-01-26] Accepted ruby-icalendar 2.7.1-1 (source) into unstable (Cédric Boutillier)
  • [2022-01-21] ruby-icalendar REMOVED from testing (Debian testing watch)
  • [2018-12-27] Accepted ruby-icalendar 2.4.1-2~bpo9+1 (source all) into stretch-backports, stretch-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-12-01] ruby-icalendar 2.4.1-2 MIGRATED to testing (Debian testing watch)
  • [2018-11-28] Accepted ruby-icalendar 2.4.1-2 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2018-11-28] ruby-icalendar REMOVED from testing (Debian testing watch)
  • [2018-09-23] ruby-icalendar 2.4.1-1 MIGRATED to testing (Debian testing watch)
  • [2018-09-20] Accepted ruby-icalendar 2.4.1-1 (source all) into unstable, unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
bugs [bug history graph]
  • all: 0
links
  • homepage
  • buildd: logs
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • debci

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing