Debian Package Tracker
Register | Log in
Subscribe

ruby-rack

modular Ruby webserver interface

Choose email to subscribe with

general
  • source: ruby-rack (main)
  • version: 2.2.3-4
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Youhei SASAKI [DMD] [DM] – Chris Lamb [DMD] – Utkarsh Gupta [DMD] – Paul van Tilburg [DMD] – Lucas Nussbaum [DMD]
  • arch: all
  • std-ver: 4.6.0
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.6.4-4+deb9u1
  • o-o-sec: 1.6.4-4+deb9u2
  • o-o-bpo: 1.6.4-5~bpo9+1
  • oldstable: 2.0.6-3
  • old-bpo: 2.1.1-4~bpo10+1
  • stable: 2.1.4-3
  • testing: 2.2.3-4
  • unstable: 2.2.3-4
versioned links
  • 1.6.4-4+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.4-4+deb9u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.4-5~bpo9+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.6-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.1-4~bpo10+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.4-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.2.3-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-rack
action needed
Multiarch hinter reports 1 issue(s) high
There are issues with the multiarch metadata for this package.
  • ruby-rack could be marked Multi-Arch: foreign
Created: 2020-04-11 Last update: 2022-05-17 16:06
lintian reports 1 error and 1 warning high
Lintian reports 1 error and 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2021-09-06 Last update: 2021-09-06 18:35
3 low-priority security issues in buster low

There are 3 open security issues in buster.

3 issues left for the package maintainer to handle:
  • CVE-2020-8161: (needs triaging) A directory traversal vulnerability exists in rack < 2.2.0 that allows an attacker perform directory traversal vulnerability in the Rack::Directory app that is bundled with Rack which could result in information disclosure.
  • CVE-2020-8184: (needs triaging) A reliance on cookies without validation/integrity check security vulnerability exists in rack < 2.2.3, rack < 2.1.4 that makes it is possible for an attacker to forge a secure or host-only cookie prefix.
  • CVE-2019-16782: (needs triaging) There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison.

You can find information about how to handle these issues in the security team's documentation.

Created: 2021-02-19 Last update: 2022-02-21 02:33
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.6.1 instead of 4.6.0).
Created: 2022-05-11 Last update: 2022-05-11 23:25
news
[rss feed]
  • [2022-02-21] ruby-rack 2.2.3-4 MIGRATED to testing (Debian testing watch)
  • [2022-01-24] Accepted ruby-rack 2.2.3-4 (source) into unstable (Utkarsh Gupta)
  • [2022-01-24] Accepted ruby-rack 2.2.3-3 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-01-24] Accepted ruby-rack 2.2.3-2 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-01-23] Accepted ruby-rack 2.1.4-5 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-11-20] ruby-rack 2.1.4-4 MIGRATED to testing (Debian testing watch)
  • [2021-11-17] Accepted ruby-rack 2.1.4-4 (source) into unstable (Cédric Boutillier)
  • [2021-03-09] ruby-rack 2.1.4-3 MIGRATED to testing (Debian testing watch)
  • [2021-02-27] Accepted ruby-rack 2.1.4-3 (source) into unstable (Antonio Terceiro)
  • [2021-01-30] Accepted ruby-rack 2.2.3-1 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-01-10] ruby-rack 2.1.4-2 MIGRATED to testing (Debian testing watch)
  • [2021-01-03] Accepted ruby-rack 2.1.4-2 (source) into unstable (Utkarsh Gupta)
  • [2021-01-03] Accepted ruby-rack 2.1.4-1 (source) into unstable (Utkarsh Gupta)
  • [2021-01-02] Accepted ruby-rack 2.1.1-6 (source) into unstable (Utkarsh Gupta)
  • [2020-07-10] Accepted ruby-rack 1.6.4-4+deb9u2 (source all) into oldstable (Utkarsh Gupta)
  • [2020-05-24] ruby-rack 2.1.1-5 MIGRATED to testing (Debian testing watch)
  • [2020-05-22] Accepted ruby-rack 1.5.2-3+deb8u3 (source all) into oldoldstable (Utkarsh Gupta)
  • [2020-05-22] Accepted ruby-rack 2.1.1-5 (source) into unstable (Utkarsh Gupta)
  • [2020-04-23] Accepted ruby-rack 2.1.1-4~bpo10+1 (source all) into buster-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-04-23] Accepted ruby-rack 2.1.1-3~bpo10+1 (source all) into buster-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-04-17] ruby-rack 2.1.1-4 MIGRATED to testing (Debian testing watch)
  • [2020-04-10] Accepted ruby-rack 2.1.1-4 (source) into unstable (Utkarsh Gupta)
  • [2020-04-09] Accepted ruby-rack 2.1.1-3 (source) into unstable (Utkarsh Gupta)
  • [2020-04-09] Accepted ruby-rack 2.1.1-2 (source) into unstable (Utkarsh Gupta)
  • [2020-03-10] ruby-rack 2.0.8-1 MIGRATED to testing (Debian testing watch)
  • [2020-03-07] Accepted ruby-rack 2.0.8-1 (source) into unstable (Utkarsh Gupta)
  • [2020-01-13] Accepted ruby-rack 2.1.1-1 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2019-10-14] Accepted ruby-rack 2.0.7-2~bpo10+1 (source all) into buster-backports, buster-backports (Samyak Jain) (signed by: Sruthi Chandran)
  • [2019-09-05] ruby-rack 2.0.7-2 MIGRATED to testing (Debian testing watch)
  • [2019-09-02] Accepted ruby-rack 2.0.7-2 (source) into unstable (Utkarsh Gupta)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (1, 1)
  • buildd: logs, clang, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.1.4-5ubuntu1
  • patches for 2.1.4-5ubuntu1

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing