Bug#856683: Security - ruby-zip package vulnerable to CVE

2017-03-03 Thread Salvatore Bonaccorso
Control: reassign -1 src:ruby-zip Control: forcemerge 856269 -1 Hi On Fri, Mar 03, 2017 at 02:13:43PM -0600, Phillip Prescher wrote: > Package: ruby-zip > Version: 1.1.6-1 > > Please see CVE-2017-5946. This version of the ruby-zip package is > vulnerable to directory traversal attacks. Please up

Bug#856683: Security - ruby-zip package vulnerable to CVE

2017-03-03 Thread Phillip Prescher
Package: ruby-zip Version: 1.1.6-1 Please see CVE-2017-5946. This version of the ruby-zip package is vulnerable to directory traversal attacks. Please upgrade to 1.2.1 or apply manual patch.