Your message dated Sat, 04 Aug 2012 13:05:50 +0000
with message-id <[email protected]>
and subject line Bug#683370: fixed in ruby-actionpack-3.2 3.2.6-3
has caused the Debian Bug report #683370,
regarding CVE-2012-3424
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
683370: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=683370
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Package: ruby-actionpack-3.2
Severity: grave
Tags: security

Please see
https://groups.google.com/forum/?fromgroups#!topic/rubyonrails-security/vxJjrc15qYM
http://weblog.rubyonrails.org/2012/7/26/ann-rails-3-2-7-has-been-released/

Stable should not be affected.

The fix is here:
https://github.com/rails/rails/commit/27311fef5efa598f281649074255834546d2b4ec

Please upload an isolated fix for sid and ask for an unblock request.

Cheers,
        Moritz

--- End Message ---
--- Begin Message ---
Source: ruby-actionpack-3.2
Source-Version: 3.2.6-3

We believe that the bug you reported is fixed in the latest version of
ruby-actionpack-3.2, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Antonio Terceiro <[email protected]> (supplier of updated ruby-actionpack-3.2 
package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Format: 1.8
Date: Sat, 04 Aug 2012 09:28:12 -0300
Source: ruby-actionpack-3.2
Binary: ruby-actionpack-3.2
Architecture: source all
Version: 3.2.6-3
Distribution: unstable
Urgency: high
Maintainer: Debian Ruby Extras Maintainers 
<[email protected]>
Changed-By: Antonio Terceiro <[email protected]>
Description: 
 ruby-actionpack-3.2 - web-flow and rendering framework putting the VC in MVC 
(part of R
Closes: 683370
Changes: 
 ruby-actionpack-3.2 (3.2.6-3) unstable; urgency=high
 .
   * Add patch by Aaron Patterson for CVE-2012-3424 (Closes: #683370)
Checksums-Sha1: 
 0ae3496e0460bdc61335947542d266ca73ed2463 1683 ruby-actionpack-3.2_3.2.6-3.dsc
 9fc945d972f684dfb8f2253aa94ec053045ef116 3205 
ruby-actionpack-3.2_3.2.6-3.debian.tar.gz
 b1af91007709f34df3b3939b99cf3ebaa277f615 387422 
ruby-actionpack-3.2_3.2.6-3_all.deb
Checksums-Sha256: 
 172b28772d40a9e23ae98d716f053117eaaa8b57d98cdbce8be302fc1986bd89 1683 
ruby-actionpack-3.2_3.2.6-3.dsc
 7ff44fc20764da0bb4f80060469333f9783e58a14435657ed0e5a94f6b8579e1 3205 
ruby-actionpack-3.2_3.2.6-3.debian.tar.gz
 63fdc348fd3965a1f1583a151ad663431f0fe57d28bdbab595e5516f28184f44 387422 
ruby-actionpack-3.2_3.2.6-3_all.deb
Files: 
 e85a2a8fbab4cc190628d2864f96609b 1683 ruby optional 
ruby-actionpack-3.2_3.2.6-3.dsc
 6c381ca808b2a5d0d1eb6212e53fcb49 3205 ruby optional 
ruby-actionpack-3.2_3.2.6-3.debian.tar.gz
 39bb16e275c48dac6adfafa9063c85b8 387422 ruby optional 
ruby-actionpack-3.2_3.2.6-3_all.deb

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iEYEARECAAYFAlAdGs8ACgkQDOM8kQ+cso/baQCfSKylm/XxtfDnxBl7g/hL9dOW
hLEAninOyEkVo4ZY6Cas5dsy8mY7QQ6b
=vryH
-----END PGP SIGNATURE-----

--- End Message ---
_______________________________________________
Pkg-ruby-extras-maintainers mailing list
[email protected]
http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-ruby-extras-maintainers

Reply via email to