Bug#686867: jruby: CVE-2011-4838

2012-09-20 Thread Moritz Muehlenhoff
On Thu, Sep 20, 2012 at 12:10:30PM -0700, tony mancill wrote: > On 09/20/2012 07:05 AM, Hideki Yamane wrote: > > It's my mistake that using static version for symlink... sorry for the > > mess. > > And a bit confusion for versioning, so prepared fix as below. > > If it seems to be okay, I'll up

Bug#686867: jruby: CVE-2011-4838

2012-09-20 Thread tony mancill
On 09/20/2012 07:05 AM, Hideki Yamane wrote: > It's my mistake that using static version for symlink... sorry for the mess. > And a bit confusion for versioning, so prepared fix as below. > If it seems to be okay, I'll upload to unstable. Hello Hideki, Thank you for the quick response. The 2n

Bug#686867: jruby: CVE-2011-4838

2012-09-20 Thread Hideki Yamane
On Thu, 20 Sep 2012 23:05:38 +0900 Hideki Yamane wrote: > > > $ ls -al /usr/share/java/nailgun* previous one is wrong, send again... (I misunderstood debian/package.link extract * to correspond file) diff -Nru nailgun-0.7.1+trunk95/debian/changelog nailgun-0.9.0+trunk95/debian/changelog ---

Bug#686867: jruby: CVE-2011-4838

2012-09-20 Thread Hideki Yamane
On Wed, 19 Sep 2012 21:16:51 -0700 tony mancill wrote: > Thank you for attaching the patch. I have it applying cleanly and am in > the process of preparing an upload. However, currently the jruby > package is FTBFS due to an issue with one of its build-deps, nailgun, > which is installing a bad

Bug#686867: jruby: CVE-2011-4838

2012-09-19 Thread tony mancill
On 09/18/2012 03:17 PM, Moritz Mühlenhoff wrote: > tags 686867 patch > thanks > > On Thu, Sep 06, 2012 at 10:03:58PM +0200, Moritz Muehlenhoff wrote: >> Package: jruby >> Severity: grave >> Tags: security >> Justification: user security hole >> >> Hi, >> jruby in Wheezy is still affected by >> ht

Bug#686867: jruby: CVE-2011-4838

2012-09-18 Thread Moritz Mühlenhoff
tags 686867 patch thanks On Thu, Sep 06, 2012 at 10:03:58PM +0200, Moritz Muehlenhoff wrote: > Package: jruby > Severity: grave > Tags: security > Justification: user security hole > > Hi, > jruby in Wheezy is still affected by > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4838

Bug#686867: jruby: CVE-2011-4838

2012-09-06 Thread Moritz Muehlenhoff
Package: jruby Severity: grave Tags: security Justification: user security hole Hi, jruby in Wheezy is still affected by http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-4838 http://www.nruns.com/_d