[Bug 1119256] Re: rails: CVE-2013-0333: Vulnerability in JSON Parser

2013-02-13 Thread Stefan Sänger
and finally - here is the package I created. Is it the common way to just add these updates here in launchpad? ** Attachment added: "ruby-activesupport-2.3_2.3.14-3ubuntu0.12.04.1_all.deb" https://bugs.launchpad.net/ubuntu/+source/ruby-activesupport-2.3/+bug/1119256/+attachment/3526530/+files/

[Bug 1119256] Re: rails: CVE-2013-0333: Vulnerability in JSON Parser

2013-02-13 Thread Stefan Sänger
Hi guys, here is the debdiff I created. In addition, I really just added the patch to debian/patches and updated series and changelog accordingly. ** Patch added: "debdiff" https://bugs.launchpad.net/ubuntu/+source/ruby-activesupport-2.3/+bug/1119256/+attachment/3526529/+files/ruby-activesuppo

[Bug 1119256] Re: rails: CVE-2013-0333: Vulnerability in JSON Parser

2013-02-11 Thread Stefan Sänger
Hi all, I am not sure why there is so little progress here. The patch I attached is the one mentioned in debian bugtracker, and I provided the link in my initial report. Also, I tried to build a new package containing the patch for myself - which was rather easy, since I only had to adjust changel

[Bug 1119256] Re: rails: CVE-2013-0333: Vulnerability in JSON Parser

2013-02-09 Thread Stefan Sänger
Hi Marc, I just had a closer look. The only difference that has been done by Debian developer team is to add CVE-2013-0333.patch - very similar to what you have done for CVE-2013-0156. So, I just added the patch from debian package here. ** CVE added: http://www.cve.mitre.org/cgi- bin/cvename.cgi

[Bug 1119256] [NEW] rails: CVE-2013-0333: Vulnerability in JSON Parser

2013-02-08 Thread Stefan Sänger
*** This bug is a security vulnerability *** Public security bug reported: The CVE mentioned in summary caused quite some media attention in germany. According to http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=699249#19 this problem is solved in debian upstream, but there has been no securit