Overview

Request 223117 accepted

- fix CVE-2014-0081: XSS Vulnerability in number_to_currency,
number_to_percentage and number_to_human (bnc#864433)
- fix CVE-2014-0082: Denial of Service Vulnerability in Action View
when using render :text (bnc#864431)
- added patches:
* CVE-2014-0081.patch: contains fix for CVE-2014-0081
* CVE-2014-0082.patch: contains fix for CVE-2014-0082

Request History
Jordi Massaguer's avatar

jordimassaguerpla created request

- fix CVE-2014-0081: XSS Vulnerability in number_to_currency,
number_to_percentage and number_to_human (bnc#864433)
- fix CVE-2014-0082: Denial of Service Vulnerability in Action View
when using render :text (bnc#864431)
- added patches:
* CVE-2014-0081.patch: contains fix for CVE-2014-0081
* CVE-2014-0082.patch: contains fix for CVE-2014-0082


Marcus Meissner's avatar

msmeissn accepted request

ok

openSUSE Build Service is sponsored by