Update to Ruby 2.6.5, fixing the following vulnerabilities:

* CVE-2019-16255: A code injection vulnerability of Shell#[] and Shell#test
* CVE-2019-16254: HTTP response splitting in WEBrick (Additional fix)
* CVE-2019-15845: A NUL injection vulnerability of File.fnmatch and File.fnmatch?
* CVE-2019-16201: Regular Expression Denial of Service vulnerability of WEBrick.s Digest access authentication
This commit is contained in:
jeremy 2019-10-03 18:38:54 +00:00
parent 755f1cb616
commit f6c2326c22
3 changed files with 6 additions and 6 deletions

View File

@ -1,6 +1,6 @@
# $OpenBSD: Makefile,v 1.7 2019/08/30 15:58:26 jeremy Exp $ # $OpenBSD: Makefile,v 1.8 2019/10/03 18:38:54 jeremy Exp $
VERSION = 2.6.4 VERSION = 2.6.5
DISTNAME = ruby-${VERSION} DISTNAME = ruby-${VERSION}
SHARED_LIBS = ruby26 0.0 SHARED_LIBS = ruby26 0.0
NEXTVER = 2.7 NEXTVER = 2.7

View File

@ -1,2 +1,2 @@
SHA256 (ruby-2.6.4.tar.gz) = T8HYunVQWzeXAgpv/IWovP9q3E2rrjQ7ZXK/KB7heTc= SHA256 (ruby-2.6.5.tar.gz) = ZpdrcW7MH9NPm3w8Kwe703YxgVN3ouPoWlsZTP3L7X0=
SIZE (ruby-2.6.4.tar.gz) = 16503137 SIZE (ruby-2.6.5.tar.gz) = 16172159

View File

@ -1,4 +1,4 @@
@comment $OpenBSD: PLIST-main,v 1.5 2019/08/30 15:58:26 jeremy Exp $ @comment $OpenBSD: PLIST-main,v 1.6 2019/10/03 18:38:54 jeremy Exp $
@option no-default-conflict @option no-default-conflict
@conflict ruby->=2.6,<2.7 @conflict ruby->=2.6,<2.7
bin/bundle26 bin/bundle26
@ -42,7 +42,7 @@ include/ruby-${REV}/ruby/util.h
include/ruby-${REV}/ruby/version.h include/ruby-${REV}/ruby/version.h
include/ruby-${REV}/ruby/vm.h include/ruby-${REV}/ruby/vm.h
include/ruby-${REV}/${SUB}/ include/ruby-${REV}/${SUB}/
include/ruby-${REV}/${SUB}/rb_mjit_min_header-2.6.4.h include/ruby-${REV}/${SUB}/rb_mjit_min_header-2.6.5.h
include/ruby-${REV}/${SUB}/ruby/ include/ruby-${REV}/${SUB}/ruby/
include/ruby-${REV}/${SUB}/ruby/config.h include/ruby-${REV}/${SUB}/ruby/config.h
lib/libruby26.so lib/libruby26.so