Debian Package Tracker
Register | Log in
Subscribe

ruby-rack

modular Ruby webserver interface

Choose email to subscribe with

general
  • source: ruby-rack (main)
  • version: 2.2.4-3
  • maintainer: Debian Ruby Team (archive) (DMD)
  • uploaders: Lucas Nussbaum [DMD] – Paul van Tilburg [DMD] – Utkarsh Gupta [DMD] – Chris Lamb [DMD] – Youhei SASAKI [DMD] [DM]
  • arch: all
  • std-ver: 4.6.2
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 1.6.4-4+deb9u1
  • o-o-sec: 1.6.4-4+deb9u2
  • o-o-bpo: 1.6.4-5~bpo9+1
  • oldstable: 2.0.6-3
  • old-sec: 2.0.6-3+deb10u2
  • old-bpo: 2.1.1-4~bpo10+1
  • stable: 2.1.4-3
  • testing: 2.2.4-3
  • unstable: 2.2.4-3
  • exp: 3.0.0-1
versioned links
  • 1.6.4-4+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.4-4+deb9u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 1.6.4-5~bpo9+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.6-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.0.6-3+deb10u2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.1-4~bpo10+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.1.4-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.2.4-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 3.0.0-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • ruby-rack
action needed
A new upstream version is available: 3.0.7 high
A new upstream version 3.0.7 is available, you should consider packaging it.
Created: 2022-08-09 Last update: 2023-03-27 16:03
3 security issues in buster high

There are 3 open security issues in buster.

2 important issues:
  • CVE-2023-27530: A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.
  • CVE-2023-27539:
1 issue postponed or untriaged:
  • CVE-2019-16782: (needs triaging) There's a possible information leak / session hijack vulnerability in Rack (RubyGem rack). This vulnerability is patched in versions 1.6.12 and 2.0.8. Attackers may be able to find and hijack sessions by using timing attacks targeting the session id. Session ids are usually stored and indexed in a database that uses some kind of scheme for speeding up lookups of that session id. By carefully measuring the amount of time it takes to look up a session, an attacker may be able to find a valid session id and hijack the session. The session id itself may be generated randomly, but the way the session is indexed by the backing store does not use a secure comparison.
Created: 2023-03-09 Last update: 2023-03-27 11:06
7 security issues in bullseye high

There are 7 open security issues in bullseye.

7 important issues:
  • CVE-2022-30122: A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.
  • CVE-2022-30123: A sequence injection vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 which could allow is a possible shell escape in the Lint and CommonLogger components of Rack.
  • CVE-2022-44570: A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.
  • CVE-2022-44571: There is a denial of service vulnerability in the Content-Disposition parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This could allow an attacker to craft an input that can cause Content-Disposition header parsing in Rackto take an unexpected amount of time, possibly resulting in a denial ofservice attack vector. This header is used typically used in multipartparsing. Any applications that parse multipart posts using Rack (virtuallyall Rails applications) are impacted.
  • CVE-2022-44572: A denial of service vulnerability in the multipart parsing component of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1 and 3.0.0.1 could allow an attacker tocraft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse multipart posts using Rack (virtually all Rails applications) are impacted.
  • CVE-2023-27530: A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.
  • CVE-2023-27539:
Created: 2022-07-04 Last update: 2023-03-27 11:06
2 security issues in bookworm high

There are 2 open security issues in bookworm.

2 important issues:
  • CVE-2023-27530: A DoS vulnerability exists in Rack <v3.0.4.2, <v2.2.6.3, <v2.1.4.3 and <v2.0.9.3 within in the Multipart MIME parsing code in which could allow an attacker to craft requests that can be abuse to cause multipart parsing to take longer than expected.
  • CVE-2023-27539:
Created: 2023-03-09 Last update: 2023-03-27 11:06
The VCS repository is not up to date, push the missing commits. high
vcswatch reports that the current version of the package is not in its VCS.
Either you need to push your commits and/or your tags, or the information about the package's VCS are out of date. A common cause of the latter issue when using the Git VCS is not specifying the correct branch when the packaging is not in the default one (remote HEAD branch), which is usually "master" but can be modified in salsa.debian.org in the project's general settings with the "Default Branch" field). Alternatively the Vcs-Git field in debian/control can contain a "-b <branch-name>" suffix to indicate what branch is used for the Debian packaging.
Created: 2022-08-09 Last update: 2023-03-25 15:06
testing migrations
  • excuses:
    • Migration status for ruby-rack (2.2.4-3 to 2.2.6.4-1): Waiting for test results or another package, or too young (no action required now - check later)
    • Issues preventing migration:
    • ∙ ∙ Too young, only 2 of 5 days old
    • Additional info:
    • ∙ ∙ Piuparts tested OK - https://piuparts.debian.org/sid/source/r/ruby-rack.html
    • ∙ ∙ autopkgtest for ruby-rack/2.2.6.4-1: amd64: Pass, arm64: Pass, armel: Pass, armhf: Pass, i386: Pass, ppc64el: Pass, s390x: Pass
    • ∙ ∙ Overriding age needed from 5 days to 5 by sramacher
    • ∙ ∙ Ignoring block request by freeze, due to unblock request by sramacher
    • Not considered
news
[rss feed]
  • [2023-03-25] Accepted ruby-rack 2.2.6.4-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2023-02-13] ruby-rack 2.2.4-3 MIGRATED to testing (Debian testing watch)
  • [2023-02-10] Accepted ruby-rack 2.2.4-3 (source) into unstable (Sruthi Chandran)
  • [2023-01-30] Accepted ruby-rack 2.0.6-3+deb10u2 (source) into oldstable (Utkarsh Gupta)
  • [2022-11-09] Accepted ruby-rack 3.0.0-1 (source) into experimental (Lucas Kanashiro)
  • [2022-09-04] Accepted ruby-rack 2.0.6-3+deb10u1 (source) into oldstable (Utkarsh Gupta)
  • [2022-08-12] ruby-rack 2.2.4-2 MIGRATED to testing (Debian testing watch)
  • [2022-08-09] Accepted ruby-rack 2.2.4-2 (source) into unstable (HIGUCHI Daisuke (VDR dai)) (signed by: HIGUCHI Daisuke)
  • [2022-07-05] ruby-rack 2.2.4-1 MIGRATED to testing (Debian testing watch)
  • [2022-07-01] Accepted ruby-rack 2.2.4-1 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-02-21] ruby-rack 2.2.3-4 MIGRATED to testing (Debian testing watch)
  • [2022-01-24] Accepted ruby-rack 2.2.3-4 (source) into unstable (Utkarsh Gupta)
  • [2022-01-24] Accepted ruby-rack 2.2.3-3 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-01-24] Accepted ruby-rack 2.2.3-2 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2022-01-23] Accepted ruby-rack 2.1.4-5 (source) into unstable (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-11-20] ruby-rack 2.1.4-4 MIGRATED to testing (Debian testing watch)
  • [2021-11-17] Accepted ruby-rack 2.1.4-4 (source) into unstable (Cédric Boutillier)
  • [2021-03-09] ruby-rack 2.1.4-3 MIGRATED to testing (Debian testing watch)
  • [2021-02-27] Accepted ruby-rack 2.1.4-3 (source) into unstable (Antonio Terceiro)
  • [2021-01-30] Accepted ruby-rack 2.2.3-1 (source) into experimental (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2021-01-10] ruby-rack 2.1.4-2 MIGRATED to testing (Debian testing watch)
  • [2021-01-03] Accepted ruby-rack 2.1.4-2 (source) into unstable (Utkarsh Gupta)
  • [2021-01-03] Accepted ruby-rack 2.1.4-1 (source) into unstable (Utkarsh Gupta)
  • [2021-01-02] Accepted ruby-rack 2.1.1-6 (source) into unstable (Utkarsh Gupta)
  • [2020-07-10] Accepted ruby-rack 1.6.4-4+deb9u2 (source all) into oldstable (Utkarsh Gupta)
  • [2020-05-24] ruby-rack 2.1.1-5 MIGRATED to testing (Debian testing watch)
  • [2020-05-22] Accepted ruby-rack 1.5.2-3+deb8u3 (source all) into oldoldstable (Utkarsh Gupta)
  • [2020-05-22] Accepted ruby-rack 2.1.1-5 (source) into unstable (Utkarsh Gupta)
  • [2020-04-23] Accepted ruby-rack 2.1.1-4~bpo10+1 (source all) into buster-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • [2020-04-23] Accepted ruby-rack 2.1.1-3~bpo10+1 (source all) into buster-backports (Pirate Praveen) (signed by: Praveen Arimbrathodiyil)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 2
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, exp, reproducibility
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • debian patches
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.2.4-3

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing