Comment 17 for bug 1100188

Revision history for this message
Launchpad Janitor (janitor) wrote :

This bug was fixed in the package ruby-activerecord-3.2 - 3.2.6-2ubuntu0.1

---------------
ruby-activerecord-3.2 (3.2.6-2ubuntu0.1) quantal-security; urgency=low

  * SECURITY UPDATE: Unsafe Query Generation Risk in Ruby on Rails
    (LP: #1100188)
    - debian/patches/CVE-2013-0155: Strip nils from collections on JSON and
      XML posts. Based on upstream patch.
    - CVE-2013-0155
 -- Christian Kuersteiner <email address hidden> Wed, 16 Jan 2013 16:14:08 +0700