Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Upgrade rubyzip to version 1.3.0 or later #62

Merged
merged 1 commit into from
Oct 3, 2019

Conversation

alxddh
Copy link
Contributor

@alxddh alxddh commented Oct 3, 2019

In Rubyzip before 1.3.0, a crafted ZIP file can bypass application checks on ZIP entry sizes because data about the uncompressed size can be spoofed. This allows attackers to cause a denial of service (disk consumption).

-- https://nvd.nist.gov/vuln/detail/CVE-2019-16892

@welcome
Copy link

welcome bot commented Oct 3, 2019

Welcome! Congrats on your first pull request to Jekyll Remote Theme. If you haven't already, please be sure to check out the contributing guidelines.

@benbalter benbalter merged commit 3338e7c into benbalter:master Oct 3, 2019
@welcome
Copy link

welcome bot commented Oct 3, 2019

Congrats on getting your first pull request to Jekyll Remote Theme merged! Without amazing humans like you submitting pull requests, we couldn’t run this project. You rock! 🎉

If you're interested in tackling another bug or feature, take a look at the open issues, especially those labeled help wanted.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

2 participants