Path to this page:
Subject: CVS commit: [pkgsrc-2012Q4] pkgsrc
From: Matthias Scheler
Date: 2013-02-02 11:40:02
Message id: 20130202104002.41DAA175DD@cvs.netbsd.org
Log Message:
Pullup ticket #4052 - requested by taca
databases/ruby-activerecord3: security update
devel/ruby-activemodel: security update
devel/ruby-activesupport3: security update
devel/ruby-railties: security update
mail/ruby-actionmailer3: security update
www/ruby-actionpack3: security update
www/ruby-activeresource3: security update
www/ruby-rails3: security update
Revisions pulled up:
- databases/ruby-activerecord3/distinfo 1.18
- devel/ruby-activemodel/distinfo 1.18
- devel/ruby-activesupport3/PLIST 1.2
- devel/ruby-activesupport3/distinfo 1.19
- devel/ruby-railties/distinfo 1.18
- lang/ruby/rails.mk 1.38
- mail/ruby-actionmailer3/distinfo 1.20
- www/ruby-actionpack3/distinfo 1.19
- www/ruby-activeresource3/distinfo 1.18
- www/ruby-rails3/distinfo 1.19
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:36:12 UTC 2013
Modified Files:
pkgsrc/lang/ruby: rails.mk
Log Message:
Start update of Ruby on Rails 3.0.20.
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:37:52 UTC 2013
Modified Files:
pkgsrc/devel/ruby-activesupport3: PLIST distinfo
Log Message:
Update ruby-activesupport3 to 3.0.20.
Fix CVE-2013-0333.
There is a vulnerability in the JSON code for Ruby on Rails which
allows attackers to bypass authentication systems, inject arbitrary
SQL, inject and execute arbitrary code, or perform a DoS attack on a
Rails application.
## Rails 3.0.20 (unreleased)
* Fix XML serialization of methods that return nil to not be
considered as YAML (GH #8853 and GH #492)
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:38:40 UTC 2013
Modified Files:
pkgsrc/devel/ruby-activemodel: distinfo
Log Message:
Update ruby-activemodel to 3.0.20.
Fix CVE-2013-0333.
There is a vulnerability in the JSON code for Ruby on Rails which
allows attackers to bypass authentication systems, inject arbitrary
SQL, inject and execute arbitrary code, or perform a DoS attack on a
Rails application.
## Rails 3.0.20 (unreleased)
* Fix XML serialization of methods that return nil to not be
considered as YAML (GH #8853 and GH #492)
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:39:33 UTC 2013
Modified Files:
pkgsrc/www/ruby-activeresource3: distinfo
Log Message:
Update ruby-activeresource3 to 3.0.20.
No change except version.
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:40:43 UTC 2013
Modified Files:
pkgsrc/databases/ruby-activerecord3: distinfo
Log Message:
Update ruby-activerecord3 to 3.0.20.
No change except version.
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:41:17 UTC 2013
Modified Files:
pkgsrc/www/ruby-actionpack3: distinfo
Log Message:
Update ruby-actionpack3 to 3.0.20.
No change except version.
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:41:49 UTC 2013
Modified Files:
pkgsrc/mail/ruby-actionmailer3: distinfo
Log Message:
Update ruby-actionmailer3 to 3.0.20.
No change except version.
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:42:27 UTC 2013
Modified Files:
pkgsrc/devel/ruby-railties: distinfo
Log Message:
Update ruby-railties to 3.0.20.
No change except version.
---
Module Name: pkgsrc
Committed By: taca
Date: Tue Jan 29 15:42:58 UTC 2013
Modified Files:
pkgsrc/www/ruby-rails3: distinfo
Log Message:
Update ruby-rails3 to 3.0.20.
No change except version.
Files: