We believe that the bug you reported is fixed in the latest version of
ruby-rack-session, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1133007@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Adrian Bunk <bunk@debian.org> (supplier of updated ruby-rack-session package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sat, 02 May 2026 11:37:55 +0300
Source: ruby-rack-session
Architecture: source
Version: 2.1.1-0.2
Distribution: unstable
Urgency: medium
Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org>
Changed-By: Adrian Bunk <bunk@debian.org>
Closes: 1133007
Changes:
ruby-rack-session (2.1.1-0.2) unstable; urgency=medium
.
* Non-maintainer upload.
* CVE-2026-39324: decrypt failure falls back to accepting
unencrypted cookies (Closes: #1133007)
Checksums-Sha1:
9a9fe2a236049bc515ea0da46eb4f72ee55c05f4 2210 ruby-rack-session_2.1.1-0.2.dsc
79d6d771190d6b5b091c65278602a6d05ce0d6df 4780 ruby-rack-session_2.1.1-0.2.debian.tar.xz
Checksums-Sha256:
2359f3794311c9194bcd5e966527e12040842c800f5e935a32d81cb6486f0389 2210 ruby-rack-session_2.1.1-0.2.dsc
7dfa9f984e71888eea825a8a1e271b85ae2e9990e93534d52a6b45bac46ba9a7 4780 ruby-rack-session_2.1.1-0.2.debian.tar.xz
Files:
e5ca36ba225d4e3841dbd31a08741b01 2210 ruby optional ruby-rack-session_2.1.1-0.2.dsc
0cf4b3349736e641d31bf90882acd5f9 4780 ruby optional ruby-rack-session_2.1.1-0.2.debian.tar.xz
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEOvp1f6xuoR0v9F3wiNJCh6LYmLEFAmn1yeIACgkQiNJCh6LY
mLECQA/+MBI6yM/nJOAoqUUbYt6KW7JyLMEsOMwa6VfMhdSC7wArWdBve5Ho6VcI
eTM0LO/NEimtVjBvyJ5kU55Us1O2W4uFaMrfBYdyQsCWHn1nVkDv4IotUWJUgdTR
/9B4t5o9adIn5ZtxnlrOCq/WAJScirXErTCYMvRNpFtlj1pI2qLmH/oYK53fovgF
/wrBfZen3abqEX6wqe/gl7LK/t7FVGJhUCnhhYT8bWEO2/UkPmlFuEDwqPDYfbCI
NUjwnXY6oRE+QB8tt8veQDUGhM+VUVZuYVMkH2Xgpt6WpvI0D0LZRpc1cpUC+LdQ
aEgxDj4FO5pUtJoDlq0W2D6cCfqiwf/1+BHgzbX1OvFivkWjO2NchTwRSP0hStB3
JQTSTzUuDPl2KsobWazXV6cOrb/fB5wJpZuk97Skycdz7Lp6PEv8hPj0Ue7dNVya
a88yqWMUBvdby0C1ipYvkUmcb8E7352NJ3S+5oyoKziv0CJQXNEkd8mtVrmOpA8x
uVBmcegUhrTRsODju2ZeC/nLf6teiPG92JzqvOsCQ3HxUW7e78qF2nxic9GyNqN1
QlOtFhc8jQbbHEKD3CgiHqj1wADqwCnWTxtklZWudTRRsiwJads4O34Y8s8NpM9o
NPCQf/9Jc4fauA2nqZ7mY5sxvIfevg0peSaopgTcnVtuaGUOEUA=
=9CXN
-----END PGP SIGNATURE-----