[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

[SECURITY] [DSA 6090-1] rails security update



-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian Security Advisory DSA-6090-1                   security@debian.org
https://www.debian.org/security/                       Moritz Muehlenhoff
December 21, 2025                     https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : rails
CVE ID         : CVE-2025-24293 CVE-2025-55193

Multiple security issues were discovered in the Rails web framework
which could result in command injection or logging of unescaped ANSI
sequences.

For the oldstable distribution (bookworm), these problems have been fixed
in version 2:6.1.7.10+dfsg-1~deb12u2.

For the stable distribution (trixie), these problems have been fixed in
version 2:7.2.2.2+dfsg-2~deb13u1.

We recommend that you upgrade your rails packages.

For the detailed security status of rails please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/rails

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmlICKUACgkQEMKTtsN8
TjZS/BAApzD4MqLg5ros+9b+n2cPKhDSKE64E5PaETQNHHsRc1E+IRivSxlrRx2D
m9pCRhg8gzxeFa9prg3U6dFdte02JzLU9RfxEYzo2BPrM0Aey3qRCci7TSfvrYfQ
OUlbFICAYkFAZKj1ifzakeN9U+h+TirmPXweYXBf1LME2jrBdBNNkdziueuSEMW7
iVW8RZTbL6metKHlhHiA6zJeSqVBbryj26v2vJLZcFI1UEq/4uvz5eD9kCs7IO1u
nbFpXcxk412NQ1WPv2LKqDQKOj7as1Vy24FCHej0iwobssGyCg7n7ksOL0G6V/o2
kUK7zWLpmjz/oXYdK2lEosDXhRo9GadMkQDnzH+lx1QCcVB/YtH9gA5X/Vb++FvN
Er47uGmQDSiOGesdVKSVeQNY7daUTsj1ZWt/cc6sruj3nJydNrVbqbiQKGE2DdO0
ToCa1FAv/1hejYorR5uWPy35Vq3d72Lt4pyAUUX8qsHQTUjaw2AbgcBAgZY14JQQ
iFzewQ7ukYECLaS+rs32khFevFIt6DvYYMeeX8pv66Ob0jw9M0uvD3rCAher7mUc
ep6agsoYd9RFQtiNKOy+elluB3JvjMjb/T0EcIqK2ayuE/XPtUgt73qpG192qxuW
IOsLof2AYp1c5+vp37bPPctA+6KMJDw+QWwamtMZFAv5J3TrCHw=
=WRaw
-----END PGP SIGNATURE-----


Reply to: