File _patchinfo of Package patchinfo
<patchinfo> <issue id="CVE-2013-0263" tracker="cve" /> <issue id="CVE-2013-0262" tracker="cve" /> <category>security</category> <rating>moderate</rating> <packager>coolo</packager> <description>- updated to version 1.1.6 * Fix CVE-2013-0263, timing attack against Rack::Session::Cookie * Fix CVE-2013-0262, symlink path traversal in Rack::File - from 1.1.5: * [SEC] Rack::Auth::AbstractRequest no longer symbolizes arbitrary strings * Fixed erroneous test case in the 1.3.x series - update to version 1.1.4 </description> <summary>rubygem-rack-1_1: update to security version 1.1.6</summary> </patchinfo>