CVE-2012-3424

Related Vulnerabilities: CVE-2012-3424  

Debian Bug report logs - #683370
CVE-2012-3424

version graph

Package: ruby-actionpack-3.2; Maintainer for ruby-actionpack-3.2 is (unknown);

Reported by: Moritz Muehlenhoff <muehlenhoff@univention.de>

Date: Tue, 31 Jul 2012 08:06:01 UTC

Severity: grave

Tags: security

Fixed in version ruby-actionpack-3.2/3.2.6-3

Done: Antonio Terceiro <terceiro@debian.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, team@security.debian.org, Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org>:
Bug#683370; Package ruby-actionpack-3.2. (Tue, 31 Jul 2012 08:06:03 GMT) (full text, mbox, link).


Acknowledgement sent to Moritz Muehlenhoff <muehlenhoff@univention.de>:
New Bug report received and forwarded. Copy sent to team@security.debian.org, Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org>. (Tue, 31 Jul 2012 08:06:03 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: Moritz Muehlenhoff <muehlenhoff@univention.de>
To: Debian Bug Tracking System <submit@bugs.debian.org>
Subject: CVE-2012-3424
Date: Tue, 31 Jul 2012 10:04:14 +0200
Package: ruby-actionpack-3.2
Severity: grave
Tags: security

Please see
https://groups.google.com/forum/?fromgroups#!topic/rubyonrails-security/vxJjrc15qYM
http://weblog.rubyonrails.org/2012/7/26/ann-rails-3-2-7-has-been-released/

Stable should not be affected.

The fix is here:
https://github.com/rails/rails/commit/27311fef5efa598f281649074255834546d2b4ec

Please upload an isolated fix for sid and ask for an unblock request.

Cheers,
        Moritz



Reply sent to Antonio Terceiro <terceiro@debian.org>:
You have taken responsibility. (Sat, 04 Aug 2012 13:06:14 GMT) (full text, mbox, link).


Notification sent to Moritz Muehlenhoff <muehlenhoff@univention.de>:
Bug acknowledged by developer. (Sat, 04 Aug 2012 13:06:14 GMT) (full text, mbox, link).


Message #10 received at 683370-close@bugs.debian.org (full text, mbox, reply):

From: Antonio Terceiro <terceiro@debian.org>
To: 683370-close@bugs.debian.org
Subject: Bug#683370: fixed in ruby-actionpack-3.2 3.2.6-3
Date: Sat, 04 Aug 2012 13:05:50 +0000
Source: ruby-actionpack-3.2
Source-Version: 3.2.6-3

We believe that the bug you reported is fixed in the latest version of
ruby-actionpack-3.2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 683370@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Antonio Terceiro <terceiro@debian.org> (supplier of updated ruby-actionpack-3.2 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@debian.org)


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sat, 04 Aug 2012 09:28:12 -0300
Source: ruby-actionpack-3.2
Binary: ruby-actionpack-3.2
Architecture: source all
Version: 3.2.6-3
Distribution: unstable
Urgency: high
Maintainer: Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@lists.alioth.debian.org>
Changed-By: Antonio Terceiro <terceiro@debian.org>
Description: 
 ruby-actionpack-3.2 - web-flow and rendering framework putting the VC in MVC (part of R
Closes: 683370
Changes: 
 ruby-actionpack-3.2 (3.2.6-3) unstable; urgency=high
 .
   * Add patch by Aaron Patterson for CVE-2012-3424 (Closes: #683370)
Checksums-Sha1: 
 0ae3496e0460bdc61335947542d266ca73ed2463 1683 ruby-actionpack-3.2_3.2.6-3.dsc
 9fc945d972f684dfb8f2253aa94ec053045ef116 3205 ruby-actionpack-3.2_3.2.6-3.debian.tar.gz
 b1af91007709f34df3b3939b99cf3ebaa277f615 387422 ruby-actionpack-3.2_3.2.6-3_all.deb
Checksums-Sha256: 
 172b28772d40a9e23ae98d716f053117eaaa8b57d98cdbce8be302fc1986bd89 1683 ruby-actionpack-3.2_3.2.6-3.dsc
 7ff44fc20764da0bb4f80060469333f9783e58a14435657ed0e5a94f6b8579e1 3205 ruby-actionpack-3.2_3.2.6-3.debian.tar.gz
 63fdc348fd3965a1f1583a151ad663431f0fe57d28bdbab595e5516f28184f44 387422 ruby-actionpack-3.2_3.2.6-3_all.deb
Files: 
 e85a2a8fbab4cc190628d2864f96609b 1683 ruby optional ruby-actionpack-3.2_3.2.6-3.dsc
 6c381ca808b2a5d0d1eb6212e53fcb49 3205 ruby optional ruby-actionpack-3.2_3.2.6-3.debian.tar.gz
 39bb16e275c48dac6adfafa9063c85b8 387422 ruby optional ruby-actionpack-3.2_3.2.6-3_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlAdGs8ACgkQDOM8kQ+cso/baQCfSKylm/XxtfDnxBl7g/hL9dOW
hLEAninOyEkVo4ZY6Cas5dsy8mY7QQ6b
=vryH
-----END PGP SIGNATURE-----




Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Tue, 04 Sep 2012 07:29:34 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Wed Jun 19 18:28:57 2019; Machine Name: beach

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.