Mandatory security update

Bug #55811 reported by Andreas Simon
270
Affects Status Importance Assigned to Milestone
rails (Debian)
Fix Released
Unknown
rails (Ubuntu)
Fix Released
Undecided
Unassigned
Dapper
Fix Released
Medium
Martin Pitt

Bug Description

Binary package hint: rails

Upstream has released a "mandatory" security update.
So far they haven't disclosed any details but they rate it as "critical":

http://weblog.rubyonrails.org/2006/8/9/rails-1-1-5-mandatory-security-patch-and-other-tidbits

This problem affects 0.13, 0.14, 1.0, and 1.1.x. (i.e. all versions from breezy to edgy)

Changed in rails:
status: Unknown → Unconfirmed
Revision history for this message
Andreas Simon (andreas-w-simon) wrote :

Update: Rails <= 1.0 and Rails 1.1.3 are not affected.
That means the Rails versions in Dapper and currenty Edgy are affected.

http://weblog.rubyonrails.com/2006/8/10/security-update-rails-1-0-not-affected

Changed in rails:
status: Unconfirmed → Fix Released
Revision history for this message
hiroshi yui (hiroshiyui) wrote :

And please notice the latest 1.1.6 release infomation:

http://weblog.rubyonrails.com/2006/8/10/rails-1-1-6-backports-and-full-disclosure

Thanks.

Revision history for this message
Martin Pitt (pitti) wrote :

Requested sync to fix edgy.

Changed in rails:
status: Unconfirmed → Fix Committed
Revision history for this message
Andreas Simon (andreas-w-simon) wrote :

Will Dapper get a fix too?

Revision history for this message
Martin Pitt (pitti) wrote :

Dapper> if someone cares enough to extract, backport, and test the fixes, then yes.

Revision history for this message
Martin Pitt (pitti) wrote :

1.1.6 is in edgy.

Changed in rails:
status: Fix Committed → Fix Released
Revision history for this message
Steve Kowalik (stevenk) wrote :

This is the debdiff for the security update for Dapper. It builds and installs correctly, and I can create a base app using it.

Changed in rails:
status: Unconfirmed → Fix Committed
Revision history for this message
Martin Pitt (pitti) wrote :

Thanks, Steve!

Changed in rails:
assignee: nobody → pitti
importance: Untriaged → Medium
Revision history for this message
Martin Pitt (pitti) wrote :

published dapper update, will appear on the mirrors in about an hour.

Changed in rails:
status: Fix Committed → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Duplicates of this bug

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.