Overview

Request 356307 accepted

- fix bnc#963329 - CVE-2015-7576: rubygem-actionpack,
rubygem-activesupport: Timing attack vulnerability in basic
authentication in Action Controller
CVE-2015-7576.patch: contains the fix

- fix bnc#963332 - CVE-2016-0752: rubygem-actionpack,
rubygem-actionview: directory traversal and information leak in
Action View
CVE-2016-0752.patch: contains the security fix

- fix bnc#963335 - CVE-2015-7581: rubygem-actionpack: unbounded
memory growth DoS via wildcard controller routes
CVE-2015-7581.patch: contains the fix

- fix bnc#963331 - CVE-2016-0751: rubygem-actionpack: Object Leak DoS
CVE-2016-0751.patch: contains the fix

Request History
Jürgen Löhel's avatar

jloehel created request

- fix bnc#963329 - CVE-2015-7576: rubygem-actionpack,
rubygem-activesupport: Timing attack vulnerability in basic
authentication in Action Controller
CVE-2015-7576.patch: contains the fix

- fix bnc#963332 - CVE-2016-0752: rubygem-actionpack,
rubygem-actionview: directory traversal and information leak in
Action View
CVE-2016-0752.patch: contains the security fix

- fix bnc#963335 - CVE-2015-7581: rubygem-actionpack: unbounded
memory growth DoS via wildcard controller routes
CVE-2015-7581.patch: contains the fix

- fix bnc#963331 - CVE-2016-0751: rubygem-actionpack: Object Leak DoS
CVE-2016-0751.patch: contains the fix


Maintenance Bot's avatar

maintbot added devel:languages:ruby:extensions as a reviewer

Submission by someone who is not maintainer in the devel project. Please review


Maintenance Bot's avatar

maintbot accepted review

accepted


Jordi Massaguer's avatar

jordimassaguerpla accepted review

thanks jloehel


Jordi Massaguer's avatar

jordimassaguerpla approved review

thanks jloehel


Andreas Stieger's avatar

AndreasStieger moved maintenance target to openSUSE:Maintenance:4604


Andreas Stieger's avatar

AndreasStieger accepted request

ok

openSUSE Build Service is sponsored by