Bug#698440: ruby-rack: CVE-2012-6109 CVE-2013-0184 CVE-2013-0183

2013-02-10 Thread Satoru KURASHIKI
hi, (CC: pkg-ruby-extras-maintainers) > > > BTW, I don't know these issues affect stable packages, > > > librack-ruby{,1.8,1.9.1}, ver. 1.1.0-4. > > > > I seem to need 0003-Reimplement-auth-scheme-fix.patch. > > Please consult about this to security team. > > Ok. I prepared a patch for stable ve

Bug#698440: [DRE-maint] Bug#698440: ruby-rack: CVE-2012-6109 CVE-2013-0184 CVE-2013-0183

2013-01-26 Thread Youhei SASAKI
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi, At 22 Jan 2013 08:36:22 +0900, "Nobuhiro Iwamatsu" wrote: > > Looks good to me. Thank you for your review. I'll upload it. > > BTW, I don't know these issues affect stable packages, > > librack-ruby{,1.8,1.9.1}, ver. 1.1.0-4. > > I seem to

Bug#698440: [DRE-maint] Bug#698440: ruby-rack: CVE-2012-6109 CVE-2013-0184 CVE-2013-0183

2013-01-21 Thread Nobuhiro Iwamatsu
Hi, On Sun, Jan 20, 2013 at 6:13 AM, Youhei SASAKI wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA512 > > Dear team member: > (Cc: BTS, security team) > > I created cherry-picked patches from upstream, in order to fix these CVE > issues and commit team git repository. Please review for up

Bug#698440: [DRE-maint] Bug#698440: ruby-rack: CVE-2012-6109 CVE-2013-0184 CVE-2013-0183

2013-01-19 Thread Youhei SASAKI
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Dear team member: (Cc: BTS, security team) I created cherry-picked patches from upstream, in order to fix these CVE issues and commit team git repository. Please review for upload. Vcs-Git: git://git.debian.org/pkg-ruby-extras/ruby-rack.git Vcs

Bug#698440: ruby-rack: CVE-2012-6109 CVE-2013-0184 CVE-2013-0183

2013-01-18 Thread Moritz Muehlenhoff
Package: ruby-rack Severity: grave Tags: security Justification: user security hole Please see these links for details: http://seclists.org/oss-sec/2013/q1/80 http://seclists.org/oss-sec/2013/q1/83 Cheers, Moritz -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org wit