Packages
- ruby-sinatra - Ruby web-development dressed in a DSL
Details
It was discovered that Sinatra incorrectly handled serving static files.
An attacker could possibly use this issue to perform local file inclusion,
obtaining sensitive information.
(CVE-2022-29970)
It was discovered that Sinatra incorrectly handled special characters in
the Content-Disposition HTTP header. An attacker could possibly use this
issue to perform a reflected file download attack, achieving remote code
execution. (CVE-2022-45442)
It was discovered that Sinatra incorrectly handled serving static files.
An attacker could possibly use this issue to perform local file inclusion,
obtaining sensitive information.
(CVE-2022-29970)
It was discovered that Sinatra incorrectly handled special characters in
the Content-Disposition HTTP header. An attacker could possibly use this
issue to perform a reflected file download attack, achieving remote code
execution. (CVE-2022-45442)
Update instructions
In general, a standard system update will make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
22.04 jammy | ruby-sinatra – 2.0.8.1-2+deb11u1build0.22.04.1 | ||
20.04 focal | ruby-sinatra – 2.0.8.1-1ubuntu0.1~esm2 | ||
18.04 bionic | ruby-sinatra – 1.4.8-1ubuntu0.1~esm2 | ||
16.04 xenial | ruby-sinatra – 1.4.7-3ubuntu0.1~esm2 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.