ELA-531-1 ruby2.1 security update

multiple vulnerabilities

2021-12-27
Packageruby2.1
Version2.1.5-2+deb8u13
Related CVEs CVE-2021-41817 CVE-2021-41819


A cookie prefix spoofing vulnerability in CGI::Cookie.parse and a regular expression denial of service vulnerability (ReDoS) on date parsing methods was discovered in src:ruby2.1, the Ruby interpreter.



For Debian 8 jessie, these problems have been fixed in version 2.1.5-2+deb8u13.

We recommend that you upgrade your ruby2.1 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.