Upgrade to 2.3.15 for "extremely critical security fixes" (CVE-2013-0155) and (CVE-2013-0156)

Bug #1100590 reported by eviljoel
260
This bug affects 1 person
Affects Status Importance Assigned to Milestone
ruby-activesupport-2.3 (Ubuntu)
In Progress
Undecided
Micah Gersten

Bug Description

This critical security patch has been out for a little over a week but there has been no corresponding update to Ubuntu's packages. I suspect it might have been missed. Here is an excerpt from the Rails blog:

"I'd like to announce that 3.2.11, 3.1.10, 3.0.19, and 2.3.15 have been released. These releases contain two extremely critical security fixes so please update IMMEDIATELY.

"You can read about the security fixes by following these links:

" CVE-2013-0155 [https://groups.google.com/group/rubyonrails-security/browse_thread/thread/b75585bae4326af2]
" CVE-2013-0156 [https://groups.google.com/group/rubyonrails-security/browse_thread/thread/eb56e482f9d21934]"

Hopefully this is the right place to report this.

CVE References

information type: Private Security → Public Security
Revision history for this message
Micah Gersten (micahg) wrote :

CVE-2013-0155 doesn't apply to 2.x, I'll prepare debdiffs for CVE-2013-0156

Changed in ruby-rails-2.3 (Ubuntu):
assignee: nobody → Micah Gersten (micahg)
status: New → In Progress
Revision history for this message
Seth Arnold (seth-arnold) wrote :
Micah Gersten (micahg)
affects: ruby-rails-2.3 (Ubuntu) → ruby-activesupport-2.3 (Ubuntu)
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.