Debian 10220 Published by

A ruby2.1 security update has been released for Debian GNU/Linux 8 Extended LTS to address a cookie prefix spoofing vulnerability.



ELA-531-1 ruby2.1 security update

Package ruby2.1
Version 2.1.5-2+deb8u13
Related CVEs CVE-2021-41817 CVE-2021-41819

A cookie prefix spoofing vulnerability in CGI::Cookie.parse and a regular expression denial of service vulnerability (ReDoS) on date parsing methods was discovered in src:ruby2.1, the Ruby interpreter.

For Debian 8 jessie, these problems have been fixed in version 2.1.5-2+deb8u13.

We recommend that you upgrade your ruby2.1 packages.

Further information about Extended LTS security advisories can be found at: https://deb.freexian.com/extended-lts/

  ELA-531-1 ruby2.1 security update