Please sync rails 1.2.4-1 from Debian unstable (main)

Bug #151078 reported by Michael Bienia
260
Affects Status Importance Assigned to Milestone
rails (Ubuntu)
Fix Released
Undecided
Unassigned
Feisty
Won't Fix
Medium
Unassigned

Bug Description

Binary package hint: rails

Rationale: fixes two XSS bugs (one with a CVE id).
See also http://weblog.rubyonrails.org/2007/10/5/rails-1-2-4-maintenance-release

Debian changelog:

rails (1.2.4-1) unstable; urgency=low

  * New upstream release. Fixes at least 2 XSS bugs.
    + Secure #sanitize, #strip_tags, and #strip_links helpers against
    xss attacks. Upstream changeset 7589
    + to_json did not escape values which allows for XSS. Applied
    upstream changesets 6893, 6894. This bug as also been assigned
    designation CVE-2007-3227 (closes: #429177)
  * Add dependency on Sqlite3 as ActiveRecord supports this DB as
    well
  * Add dependency on libmocha which is needed by some unit tests

 -- Adam Majer <email address hidden> Mon, 08 Oct 2007 11:27:25 -0500

libmocha isn't included in gutsy. So I mailed the Debian maintainer if libmocha is necessary.
He said it's only used for unit test and can be removed.
I will upload a rails package without this dependency.

CVE References

Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Michael Bienia (geser) wrote :
Revision history for this message
Scott Kitterman (kitterman) wrote :

As long as you merge it to remove the depens on libmocha that we don't have, ack from me.

Revision history for this message
Chuck Short (zulcss) wrote :

ok from me

Revision history for this message
Scott Kitterman (kitterman) wrote :

geser: Approved.

Changed in rails:
status: New → Confirmed
Revision history for this message
David Portwood (dzportwood) wrote :
Revision history for this message
David Portwood (dzportwood) wrote :
Revision history for this message
David Portwood (dzportwood) wrote :

I'm not really sure what else I should upload here, I've reviewed the SRU and MOTU sponsoring uploads pages, but its a bit vague as to what exactly needs to be here. I have built and installed the package successfully on Feisty built from the upstream debian sources.

Revision history for this message
Daniel Holbach (dholbach) wrote :

This is a sync request. ACKing it.

Revision history for this message
Michael Bienia (geser) wrote :

rails (1.2.4-1ubuntu1) gutsy; urgency=low

  * debian/control:
    + Remove libmocha-ruby1.8 from Depends for rails.
      It's not included in gutsy and only used for unit tests.
    + Modify Maintainer value to match DebianMaintainerField spec.
  * UVF exception: LP: #151078

rails (1.2.4-1) unstable; urgency=low

  * New upstream release. Fixes at least 2 XSS bugs.
    + Secure #sanitize, #strip_tags, and #strip_links helpers against
    xss attacks. Upstream changeset 7589
    + to_json did not escape values which allows for XSS. Applied
    upstream changesets 6893, 6894. This bug as also been assigned
    designation CVE-2007-3227 (closes: #429177)
  * Add dependency on Sqlite3 as ActiveRecord supports this DB as
    well
  * Add dependency on libmocha which is needed by some unit tests

 -- Michael Bienia <email address hidden> Tue, 09 Oct 2007 23:01:26 +0200

Changed in rails:
status: Confirmed → Fix Released
Revision history for this message
Kees Cook (kees) wrote :

If someone can prepare (and test) the fixes and attach debdiffs that follow the [https://wiki.ubuntu.com/SecurityUpdateProcedures], I'd be more than happy to get them uploaded for the stable releases. Thanks!

Changed in rails:
importance: Undecided → Medium
status: New → Triaged
Revision history for this message
LumpyCustard (orangelumpycustard) wrote :

Please close for Feisty as Won't Fix? This goes for all the other Feisty bugs.

Revision history for this message
Hew (hew) wrote :

Ubuntu Feisty Fawn is no longer supported, so a SRU will not be issued for this release. Marking Feisty as Won't Fix.

Changed in rails:
status: Triaged → Won't Fix
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.