ruby: security bump to version 2.4.5
authorPeter Korsgaard <peter@korsgaard.com>
Tue, 30 Oct 2018 12:37:55 +0000 (13:37 +0100)
committerPeter Korsgaard <peter@korsgaard.com>
Tue, 30 Oct 2018 20:05:19 +0000 (21:05 +0100)
commit646ae5a0b1ec9e7c099de0088c333470283f7e33
tree499e9ee8a4bf8074b54a947e778b20f5b8cc1ea2
parent15793bc19f196691f6b09636ebf2c3de53d369c0
ruby: security bump to version 2.4.5

Fixes the following security issues:

- CVE-2018-16396: Tainted flags are not propagated in Array#pack and
  String#unpack with some directives
https://www.ruby-lang.org/en/news/2018/10/17/not-propagated-taint-flag-in-some-formats-of-pack-cve-2018-16396/

- CVE-2018-16395: OpenSSL::X509::Name equality check does not work correctly
https://www.ruby-lang.org/en/news/2018/10/17/openssl-x509-name-equality-check-does-not-work-correctly-cve-2018-16395/

Update hash of LEGAL as it had a few (wayback machine) URLs added/changed.

Signed-off-by: Peter Korsgaard <peter@korsgaard.com>
package/ruby/ruby.hash
package/ruby/ruby.mk