Debian 10224 Published by

A ruby2.1 security update has been released for Debian GNU/Linux 8 Extended LTS to address an issue where an attacker can smuggle a request.



ELA-290-1 ruby2.1 security update

Package ruby2.1
Version 2.1.5-2+deb8u11
Related CVEs CVE-2020-25613

A potential HTTP request smuggling vulnerability in WEBrick was reported.

WEBrick (bundled along with ruby2.1) was too tolerant against an invalid Transfer-Encoding header. This may lead to inconsistent interpretation between WEBrick and some HTTP proxy servers, which may allow the attacker to “smuggle” a request.

For Debian 8 jessie, these problems have been fixed in version 2.1.5-2+deb8u11.

We recommend that you upgrade your ruby2.1 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-290-1 ruby2.1 security update