[ANN] Rack versions 1.6.11 and 2.0.6 have been released!

Aaron Patterson <[email protected]>
Newsgroups gmane.comp.lang.ruby.rails.core,gmane.comp.lang.ruby.rails,gmane.comp.lang.ruby.general
Message-ID <[email protected]>
Hi everyone,

Rack versions 1.6.11 and 2.0.6 have been released.  Both of these releases
contain important security fixes, and you should upgrade!

Rack version 1.6.11 contains fixes for:

* [CVE-2018-16470] Possible DoS vulnerability in Rack
* [CVE-2018-16471] Possible XSS vulnerability in Rack

Rack version 2.0.6 contains a fix for:

* [CVE-2018-16470] Possible DoS vulnerability in Rack

The gem checksums are:

```
$ sha1sum *
64a0cd32f46c0ff44ffda4055048fe6309903110  rack-1.6.11.gem
b15267e1f94e69238a00a6f1bd48fb7683c03a78  rack-2.0.6.gem
```

You can read more about CVE-2018-16470 here:

  https://groups.google.com/forum/#!topic/ruby-security-ann/Dz4sRl-ktKk

You can read more about CVE-2018-16471 here:

  https://groups.google.com/forum/#!topic/ruby-security-ann/NAalCee8n6o

Thanks for reading and have a good day!

-- 
Aaron Patterson
http://tenderlovemaking.com/

-- 
You received this message because you are subscribed to the Google Groups "Ruby on Rails: Core" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To post to this group, send email to [email protected].
Visit this group at https://groups.google.com/group/rubyonrails-core.
For more options, visit https://groups.google.com/d/optout.
signature.asc (application/pgp-signature, 488 B)
-----BEGIN PGP SIGNATURE-----

iQEzBAEBCAAdFiEETOkbdaeYKOhrGqi7lTFwvLT/r8YFAlvgpXYACgkQlTFwvLT/
r8YEcQf+Id6wIDsJgl+YcQ57JJ9+O71Xpw2Mq91dLradQcpiN8tzzN8RL3kf5eX6
7qpuTAjJtz3ymS2YvNlZNyfgIXIlDbED0rQOHGMBXBH01++IQOM/4bWLEW9fNeON
DWxIbV3Q4/5eOv3SiNLa+R7+jd2Xufkycwj819NiZDAFVLCY4bmdsSMu4h/FgSEZ
zksmEAjnL7kaX+KcrXwmEaC5PjtwK+pUYdZcxr7+EM2jIwuKdfNnPLANpDvGSsM1
9KD1ABbeeyTqhXlBKQYmclQDe3c8zpH4nlpz4YFTOih4EjPpwGrOqJtD4+i12ilv
Y6oNjmgxZSPRnGgK08zlsNoHW+KD8Q==
=xThf
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.