Bug 13660

Summary: ruby-activerecord new security issue CVE-2014-3482
Product: Mageia Reporter: David Walser <luigiwalser>
Component: SecurityAssignee: Funda Wang <fundawang>
Status: RESOLVED WONTFIX QA Contact: Sec team <security>
Severity: normal    
Priority: Normal    
Version: 3   
Target Milestone: ---   
Hardware: i586   
OS: Linux   
URL: http://lwn.net/Vulnerabilities/605462/
Whiteboard:
Source RPM: ruby-activerecord-3.2.13-1.mga3.src.rpm CVE:
Status comment:
Bug Depends on: 12044    
Bug Blocks:    

Description David Walser 2014-07-02 21:45:32 CEST
A security issue fixed upstream has been announced today (July 2):
http://openwall.com/lists/oss-security/2014/07/02/5

The issue is fixed upstream in version 3.2.19.

This should be updated along with the rest of the packages in the rails suite, which would also fix Bug 12044.

Reproducible: 

Steps to Reproduce:
David Walser 2014-07-02 21:45:45 CEST

Depends on: (none) => 12044

Comment 1 David Walser 2014-07-17 21:37:33 CEST
RedHat has issued an advisory for this on July 14:
https://rhn.redhat.com/errata/RHSA-2014-0876.html

URL: (none) => http://lwn.net/Vulnerabilities/605462/

Comment 2 David Walser 2014-08-20 23:27:02 CEST
Ruby on Rails has been dropped in Cauldron and we are unable to support it.

Status: NEW => RESOLVED
Resolution: (none) => WONTFIX