[ubuntu/precise-security] ruby1.9.1 1.9.3.0-1ubuntu2.3 (Accepted)

Tyler Hicks tyhicks at canonical.com
Wed Oct 10 21:27:14 UTC 2012


ruby1.9.1 (1.9.3.0-1ubuntu2.3) precise-security; urgency=low

  * SECURITY UPDATE: Safe level bypass
    - debian/patches/CVE-2012-4464_CVE-2012-4466.patch: Remove incorrect
      string taint in exception handling methods. Based on upstream patch.
    - CVE-2012-4464
    - CVE-2012-4466
  * debian/patches/CVE-2011-1005.patch: Drop since ruby1.9.x is technically
    not affected by CVE-2011-1005. CVE-2012-4464 is the id assigned to the
    vulnerability in the ruby1.9.x branch.

Date: 2012-10-06 05:25:10.256408+00:00
Changed-By: Tyler Hicks <tyhicks at canonical.com>
https://launchpad.net/ubuntu/precise/+source/ruby1.9.1/1.9.3.0-1ubuntu2.3
-------------- next part --------------
Sorry, changesfile not available.


More information about the Precise-changes mailing list