ELA-787-1 ruby-sinatra security update

reflected file download attack

2023-01-31
Packageruby-sinatra
Version1.4.7-5+deb9u2 (stretch)
Related CVEs CVE-2022-45442


Sinatra is a domain-specific language for creating web applications in Ruby. An application is vulnerable to a reflected file download (RFD) attack that sets the Content-Disposition header of a response when the filename is derived from user-supplied input.



For Debian 9 stretch, these problems have been fixed in version 1.4.7-5+deb9u2.

We recommend that you upgrade your ruby-sinatra packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.