Bug#895778: jruby: Several security vulnerabilities

2018-04-29 Thread Markus Koschany
Hi Miguel, I have prepared security updates for Jessie and Stretch. Unfortunately I discovered that jruby in Jessie FTBFS at the moment. This is unrelated to the patches. Do you know how to resolve that? generate-method-classes: _gmc_internal_: [echo] Generating invokers... [java]

Bug#895778: jruby: Several security vulnerabilities

2018-04-16 Thread Miguel Landaeta
On Sun, Apr 15, 2018 at 10:48:10PM +0200, Markus Koschany wrote: > I intend to work on the patches for Jessie and Stretch. Unstable could > be a bit more complicated due to the FTBFS with OpenJDK 9. Hi Markus, Thanks for taking care of jessie and stretch. I expect to be able to update jruby in

Bug#895778: jruby: Several security vulnerabilities

2018-04-15 Thread Markus Koschany
I intend to work on the patches for Jessie and Stretch. Unstable could be a bit more complicated due to the FTBFS with OpenJDK 9. Markus signature.asc Description: OpenPGP digital signature

Bug#895778: jruby: Several security vulnerabilities

2018-04-15 Thread Markus Koschany
Package: jruby X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for jruby. Apparently rubygems is embedded into jruby which makes it vulnerable to. CVE-2018-179[0]: | RubyGems version Ruby 2.2 series: 2.2.9 and earlier,