[DRE-maint] Bug#949870: ruby-geocoder: CVE-2020-7981

Salvatore Bonaccorso carnil at debian.org
Sun Jan 26 13:07:15 GMT 2020


Source: ruby-geocoder
Version: 1.5.1-1
Severity: grave
Tags: security upstream

Hi,

The following vulnerability was published for ruby-geocoder.

CVE-2020-7981[0]:
| sql.rb in Geocoder before 1.6.1 allows Boolean-based SQL injection
| when within_bounding_box is used in conjunction with untrusted sw_lat,
| sw_lng, ne_lat, or ne_lng data.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2020-7981
    https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-7981
[1] https://github.com/alexreisner/geocoder/commit/dcdc3d8675411edce3965941a2ca7c441ca48613

Regards,
Salvatore



More information about the Pkg-ruby-extras-maintainers mailing list