lp:ubuntu/intrepid-updates/ruby1.8

Created by James Westby and last modified
Get this branch:
bzr branch lp:ubuntu/intrepid-updates/ruby1.8
Members of Ubuntu branches can upload to this branch. Log in for directions.

Branch merges

Related bugs

Related blueprints

Branch information

Owner:
Ubuntu branches
Review team:
Ubuntu Development Team
Status:
Development

Recent revisions

25. By Marc Deslauriers

* SECURITY UPDATE: certificate spoofing via invalid return value check
  in OCSP_basic_verify
  - debian/patches/906_security_CVE-2009-0642.dpatch: also check for -1
    return code in ext/openssl/ossl_ocsp.c.
  - CVE-2009-0642
* SECURITY UPDATE: denial of service in BigDecimal library via string
  argument that represents a large number (LP: #385436)
  - debian/patches/907_security_CVE-2009-1904.dpatch: handle large
    numbers properly in ext/bigdecimal/bigdecimal.c.
  - CVE-2009-1904

24. By Jamie Strandboge

debian/patches/905_short_named_constants.dpatch: Fix for short-named
constants regression (LP: #282302)

23. By Marc Deslauriers

* SECURITY UPDATE: certificate spoofing via invalid return value check
  in OCSP_basic_verify
  - debian/patches/906_security_CVE-2009-0642.dpatch: also check for -1
    return code in ext/openssl/ossl_ocsp.c.
  - CVE-2009-0642
* SECURITY UPDATE: denial of service in BigDecimal library via string
  argument that represents a large number (LP: #385436)
  - debian/patches/907_security_CVE-2009-1904.dpatch: handle large
    numbers properly in ext/bigdecimal/bigdecimal.c.
  - CVE-2009-1904

22. By Lucas Nussbaum

* New upstream release.
  - many patches in 1.8.7.22-4 were simply backported from upstream SVN, and
    are integrated into that release. We drop those:
    + 103_array_c_r17472_to_r17756.dpatch
    + 810_ruby187p22_fixes.dpatch
    + 811_multiple_vuln_200808.dpatch
  - Fixes the following security issues: (Closes: #494401)
    * Several vulnerabilities in safe level
    * DoS vulnerability in WEBrick
    * Lack of taintness check in dl
    * DNS spoofing vulnerability in resolv.rb (CVE-2008-1447)
* Applied debian/patches/168_rexml_dos.dpatch:
  Fix CVE-2008-3790 (REXML expansion DOS). Closes: #496808.

21. By daigo

* New upstream release.
* Fixed vulnerability: arbitrary code execution vulnerability and so on
  (Closes: #487238)

20. By daigo

* New upstream release.
* removed patches that the upstream has included:
  - debian/patches/201_erb_187_release.dpatch
  - debian/patches/202_delegate_187_release.dpatch
  - debian/patches/203_openssl_ctx_r187_release.dpatch
* debian/watch: it will report 1.8.\d-p\d* versions.

19. By daigo

[ Daigo Moriwaki ]
* applied debian/patches/201_erb_187_release.dpatch:
  - fixed a bug where tokens are not yilelded one by one.
  - fixed a bug caused by strscan incompatibility.
* applied debian/patches/202_delegate_187_release.dpatch:
  - fixed a bug caused by marshal.c incompatibility.

[ Lucas Nussbaum ]
* applied debian/patches/203_openssl_ctx_r187_release.dpatch:
  - might help with Debian bug #483974

18. By Michael Vogt

* Merge from debian unstable, remaining changes:
  - Adjust configure options for lpia.
  - add -g when build with noopt

17. By LaMont Jones

Trigger rebuild for hppa

16. By Matthias Klose

* Fix build failure on sparc N1 (Debian #393817).
* Add -g to CFLAGS.

Branch metadata

Branch format:
Branch format 7
Repository format:
Bazaar repository format 2a (needs bzr 1.16 or later)
Stacked on:
lp:ubuntu/karmic/ruby1.8
This branch contains Public information 
Everyone can see this information.

Subscribers