summaryrefslogtreecommitdiff
path: root/system/ruby/CVE-2020-8130.patch
diff options
context:
space:
mode:
authorA. Wilcox <awilcox@wilcox-tech.com>2020-03-28 21:20:16 +0000
committerA. Wilcox <awilcox@wilcox-tech.com>2020-03-28 21:20:16 +0000
commitd5a2d4b0847392305e7de2bca65d30987bd0ca7e (patch)
tree6abd9673142dfece523ff5e5379b862080aa0e65 /system/ruby/CVE-2020-8130.patch
parent2e865b057fa79fa5f65240dd6634c91824f3f480 (diff)
parent29d357bdc4c7296befb3b35cd3ac3d17aa561bdb (diff)
downloadpackages-d5a2d4b0847392305e7de2bca65d30987bd0ca7e.tar.gz
packages-d5a2d4b0847392305e7de2bca65d30987bd0ca7e.tar.bz2
packages-d5a2d4b0847392305e7de2bca65d30987bd0ca7e.tar.xz
packages-d5a2d4b0847392305e7de2bca65d30987bd0ca7e.zip
Merge branch 'bump/misc/2020.03.23' into 'master'
Miscellaneous bumps for 2020.03.23 See merge request adelie/packages!417
Diffstat (limited to 'system/ruby/CVE-2020-8130.patch')
-rw-r--r--system/ruby/CVE-2020-8130.patch18
1 files changed, 18 insertions, 0 deletions
diff --git a/system/ruby/CVE-2020-8130.patch b/system/ruby/CVE-2020-8130.patch
new file mode 100644
index 000000000..3cb6e4adf
--- /dev/null
+++ b/system/ruby/CVE-2020-8130.patch
@@ -0,0 +1,18 @@
+Note: adjusted paths since it's being vendored inside ruby.
+
+From 5b8f8fc41a5d7d7d6a5d767e48464c60884d3aee Mon Sep 17 00:00:00 2001
+From: Hiroshi SHIBATA <hsbt@ruby-lang.org>
+Date: Mon, 22 Jul 2019 10:23:43 +0900
+Subject: [PATCH] Use File.open explicitly.
+
+--- ruby-2.5.7/gems/rake-12.3.0/lib/rake/file_list.rb
++++ ruby-2.5.7/gems/rake-12.3.0/lib/rake/file_list.rb
+@@ -294,7 +294,7 @@ def egrep(pattern, *options)
+ matched = 0
+ each do |fn|
+ begin
+- open(fn, "r", *options) do |inf|
++ File.open(fn, "r", *options) do |inf|
+ count = 0
+ inf.each do |line|
+ count += 1