Re: Debian Ruby sprint 2015 - Paris, 8-10 April

2015-01-26 Thread Sebastien Badia
On Sat, Jan 24, 2015 at 03:58:08PM (+0100), Cédric Boutillier wrote: Hi, Thanks for the people who answered already, by email or via IRC. If you haven't done it, add your name to the wiki Hi, Sorry for the late reply, I'm also interested by this sprint! I just added myself to the wiki page (a

Re: #774748: ruby-redcloth: CVE-2012-6684

2015-01-26 Thread Christian Hofstaedtler
* Moritz Mühlenhoff [150126 13:45]: > On Fri, Jan 09, 2015 at 10:57:13PM +0100, Christian Hofstaedtler wrote: > > AFAICT there is no publicly available patch, and upstream is more or > > less "dead". > > > > Redmine's patched redcloth3 looks very different from the current > > redcloth 4.x source

Re: #774748: ruby-redcloth: CVE-2012-6684

2015-01-26 Thread Moritz Mühlenhoff
On Fri, Jan 09, 2015 at 10:57:13PM +0100, Christian Hofstaedtler wrote: > AFAICT there is no publicly available patch, and upstream is more or > less "dead". > > Redmine's patched redcloth3 looks very different from the current > redcloth 4.x sources, so I have my doubts if forward porting this >