ruby1.9.1 1.9.3.194-7ubuntu1 source package in Ubuntu

Changelog

ruby1.9.1 (1.9.3.194-7ubuntu1) raring; urgency=low

  * Merge from Debian testing (LP: #1131493). Remaining changes:
    - debian/control: Add ca-certificates to libruby1.9.1 depends so that
      rubygems can perform certificate verification
    - debian/rules: Don't install SSL certificates from upstream sources
    - debian/patches/20120927-rubygems_disable_upstream_certs.patch: Use
      /etc/ssl/certs/ca-certificates.crt for the trusted CA certificates.
  * Changes dropped:
    - debian/patches/20121016-cve_2012_4522.patch: Debian is carrying a patch
      for this issue.
    - debian/patches/20121011-cve_2012_4464-cve_2012_4466.patch: Debian is
      carrying a patch for this issue, but the patch is incorrectly named
      20120927-cve_2011_1005.patch. I'll work with Debian to change the patch
      name, but there's no need in carrying a delta because of this. To be
      clear, the Ubuntu ruby1.9.1 package is patched for CVE-2012-4464 and
      CVE-2012-4466, despite the incorrect patch name.
  * debian/patches/CVE-2012-4522.patch: Adjust patch to fix build test error.
    Use the version of the fix from upstream's 1.9.3 tree to fix the
    NoMethodError for assert_file_not, which doesn't exist in 1.9.3. Adjust
    the Origin patch tag accordingly.

ruby1.9.1 (1.9.3.194-7) unstable; urgency=high

  * debian/patches/CVE-2013-0269.patch: fix possible denial of service and
    unsafe object creation vulnerability in JSON (Closes: #700471)

ruby1.9.1 (1.9.3.194-6) unstable; urgency=high

  [Nobuhiro Iwamatsu]
  * debian/patches/CVE-2013-0256.patch: fix possible cross site scripting
    vulnerability in documentation generated by RDOC (Closes: #699929)

ruby1.9.1 (1.9.3.194-5) unstable; urgency=high

  * Disable running the test suite during the build on sparc again. Keeping
    urgency=high because the previous release, which contains a security bug
    fix, did not reach testing yet because of a segfault when running tests in
    the sparc buildd.

ruby1.9.1 (1.9.3.194-4) unstable; urgency=high

  [ James Healy ]
  * debian/patches/CVE-2012-5371.patch: avoid DOS vulnerability in hash
    implementation, this fixes CVE-2012-5371. (Closes: #693024).

ruby1.9.1 (1.9.3.194-3) unstable; urgency=high

  * debian/patches/CVE-2012-4522.patch: avoid vulnerability with strings
    containing NUL bytes passed to file creation methods. This fixes
    CVE-2012-4522 (Closes: #690670).

ruby1.9.1 (1.9.3.194-2) unstable; urgency=low

  * debian/patches/20120927-cve_2011_1005.patch: patch sent by upstream;
    fixes CVE-2011-1005 which was thought of as not affecting the Ruby 1.9.x
    series (Closes: #689075). Thanks to Tyler Hicks <email address hidden>
    for reporting the issue.
 -- Tyler Hicks <email address hidden>   Thu, 21 Feb 2013 17:11:23 -0800

Upload details

Uploaded by:
Tyler Hicks
Sponsored by:
Marc Deslauriers
Uploaded to:
Raring
Original maintainer:
Ubuntu Developers
Architectures:
any all
Section:
ruby
Urgency:
Very Urgent

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ruby1.9.1_1.9.3.194.orig.tar.gz 11.9 MiB 46e2fa80be7efed51bd9cdc529d1fe22ebc7567ee0f91db4ab855438cf4bd8bb
ruby1.9.1_1.9.3.194-7ubuntu1.debian.tar.gz 61.6 KiB f0aace5a1de6b782ff20f6f148b2ba85f64485c7509023f5cda1544c8ba8ac0b
ruby1.9.1_1.9.3.194-7ubuntu1.dsc 2.7 KiB 1a063ec5ed78a2c91a8bfdac4655dd74917628097d3b6c8c9d7494510fa8fa8e

View changes file

Binary packages built by this source

libruby1.9.1: No summary available for libruby1.9.1 in ubuntu raring.

No description available for libruby1.9.1 in ubuntu raring.

libruby1.9.1-dbg: No summary available for libruby1.9.1-dbg in ubuntu raring.

No description available for libruby1.9.1-dbg in ubuntu raring.

libtcltk-ruby1.9.1: No summary available for libtcltk-ruby1.9.1 in ubuntu raring.

No description available for libtcltk-ruby1.9.1 in ubuntu raring.

ri1.9.1: No summary available for ri1.9.1 in ubuntu raring.

No description available for ri1.9.1 in ubuntu raring.

ruby1.9.1: No summary available for ruby1.9.1 in ubuntu raring.

No description available for ruby1.9.1 in ubuntu raring.

ruby1.9.1-dev: No summary available for ruby1.9.1-dev in ubuntu raring.

No description available for ruby1.9.1-dev in ubuntu raring.

ruby1.9.1-examples: No summary available for ruby1.9.1-examples in ubuntu raring.

No description available for ruby1.9.1-examples in ubuntu raring.

ruby1.9.1-full: No summary available for ruby1.9.1-full in ubuntu raring.

No description available for ruby1.9.1-full in ubuntu raring.

ruby1.9.3: No summary available for ruby1.9.3 in ubuntu raring.

No description available for ruby1.9.3 in ubuntu raring.