Public bug reported: The lastest Ubuntu release of rails for all supported releases does not contain the fix for CVE-2019-5418 and CVE-2019-5419.
Upstream commit: f4c70c2222180b8d9d924f00af0c7fd632e26715 Affected files: actionpack/lib/action_dispatch/http/mime_negotiation.rb actionpack/test/controller/mime/respond_to_test.rb actionpack/test/controller/new_base/content_negotiation_test.rb ** Affects: rails (Ubuntu) Importance: Undecided Assignee: Mark Thomas (markthomas) Status: New -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1820138 Title: Apply upstream fix for CVE-2019-5418 and CVE-2019-5419 To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/rails/+bug/1820138/+subscriptions -- ubuntu-bugs mailing list ubuntu-bugs@lists.ubuntu.com https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs