Bug#812103: Patch

2016-07-05 Thread Trent Lloyd
I fixed this issue in Ubuntu Precise ( https://bugs.launchpad.net/ubuntu/+source/passenger/+bug/1575220), sharing the fix here however this fix was uploaded under the Squeeze LTS project that concluded in February so I am guessing this may never be uploaded in Debian. The current patch modifies th

Bug#812103: Same problem here

2016-05-06 Thread François Trahan
On Ubuntu Ubuntu 12.04.5 Redmine: 1.3.2+dfsg1-1ubuntu1 Rails: 2.3.14-2 libapache2-mod-passenger: I get the same problem using version 2.2.11debian-2+deb6u1ubuntu12.04.1 Reverting to 2.2.11debian-2 fixes the problem. That being said, this is a security issue and it's been out for a few months n

Bug#812103: CVE-2015-7519

2016-04-26 Thread Raphael Geissert
On 26 April 2016 at 10:27, Linus van Geuns wrote: > On Tue, Apr 26, 2016 at 10:08 AM, Raphael Geissert wrote: >> On 19 February 2016 at 09:35, Linus van Geuns wrote: >>> On Thu, Feb 18, 2016 at 8:35 PM, Thorsten Alteholz >>> wrote: On irc you wrote: 15:05 < Nirkus> have some old redm

Bug#812103: CVE-2015-7519

2016-04-26 Thread Linus van Geuns
Hi, On Tue, Apr 26, 2016 at 10:08 AM, Raphael Geissert wrote: > Hi, > > On 19 February 2016 at 09:35, Linus van Geuns wrote: >> On Thu, Feb 18, 2016 at 8:35 PM, Thorsten Alteholz >> wrote: >>> On irc you wrote: >>> 15:05 < Nirkus> have some old redmine running on squeeze-lts (yeah..) and >>

Bug#812103: CVE-2015-7519

2016-04-26 Thread Raphael Geissert
Hi, On 19 February 2016 at 09:35, Linus van Geuns wrote: > On Thu, Feb 18, 2016 at 8:35 PM, Thorsten Alteholz wrote: >> On irc you wrote: >> 15:05 < Nirkus> have some old redmine running on squeeze-lts (yeah..) and >> since the update yesterday the following redmine code bails out with >> "pri

Bug#812103: CVE-2015-7519

2016-02-19 Thread Linus van Geuns
Hi Thorsten, On Thu, Feb 18, 2016 at 8:35 PM, Thorsten Alteholz wrote: > > [..] > On irc you wrote: > 15:05 < Nirkus> have some old redmine running on squeeze-lts (yeah..) and > since the update yesterday the following redmine code bails out with "private > method `split' called for nil:NilClas

Bug#812103: CVE-2015-7519

2016-02-18 Thread Thorsten Alteholz
Hi Linus, as others might be interested in the answer as well, I also send it to debian-lts@. On irc you wrote: 15:05 < Nirkus> have some old redmine running on squeeze-lts (yeah..) and since the update yesterday the following redmine code bails out with "private method `split' called for ni

Bug#812103:

2016-01-21 Thread Rémi Verchère
I confirm the bug. When downgrading to version 2.2.11debian-2, no issues. Redmine environment: Redmine version 2.2.3.stable.11436 Ruby version 1.8.7 (x86_64-linux) Rails version3.2.12 Here are the Apache logs:

Bug#812103: libapache2-mod-passenger: redmine regression after mod-passenger upgrade

2016-01-20 Thread Bernhard M. Wiedemann
Package: libapache2-mod-passenger Version: 2.2.11debian-2+deb6u1 Severity: normal I recently upgraded libapache2-mod-passenger from 2.2.11debian-2 to 2.2.11debian-2+deb6u1 and found that our redmine 1.2.0.stable (which is not installed from packages and likely obsolete) would no more start with