[ubuntu/precise-security] ruby1.9.1 1.9.3.0-1ubuntu2.6 (Accepted)

Marc Deslauriers marc.deslauriers at canonical.com
Mon Mar 25 17:29:24 UTC 2013


ruby1.9.1 (1.9.3.0-1ubuntu2.6) precise-security; urgency=low

  * SECURITY UPDATE: REXML entity expansion DoS
    - debian/patches/CVE-2013-1821.patch: set an expansion limit in
      lib/rexml/document.rb, lib/rexml/text.rb, added test to
      test/rexml/test_entity.rb.
    - Patch taken from Debian's 1.9.3.194-8.1
    - CVE-2013-1821

Date: 2013-03-22 18:55:20.522377+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
https://launchpad.net/ubuntu/precise/+source/ruby1.9.1/1.9.3.0-1ubuntu2.6
-------------- next part --------------
Sorry, changesfile not available.


More information about the Precise-changes mailing list