Bug#774748: #774748: ruby-redcloth: CVE-2012-6684

2015-01-26 Thread Christian Hofstaedtler
* Moritz Mühlenhoff [150126 13:45]: > On Fri, Jan 09, 2015 at 10:57:13PM +0100, Christian Hofstaedtler wrote: > > AFAICT there is no publicly available patch, and upstream is more or > > less "dead". > > > > Redmine's patched redcloth3 looks very different from the current > > redcloth 4.x source

Bug#774748: #774748: ruby-redcloth: CVE-2012-6684

2015-01-26 Thread Moritz Mühlenhoff
On Fri, Jan 09, 2015 at 10:57:13PM +0100, Christian Hofstaedtler wrote: > AFAICT there is no publicly available patch, and upstream is more or > less "dead". > > Redmine's patched redcloth3 looks very different from the current > redcloth 4.x sources, so I have my doubts if forward porting this >

Bug#774748: #774748: ruby-redcloth: CVE-2012-6684

2015-01-09 Thread Christian Hofstaedtler
AFAICT there is no publicly available patch, and upstream is more or less "dead". Redmine's patched redcloth3 looks very different from the current redcloth 4.x sources, so I have my doubts if forward porting this is feasible. Suggestions welcome. -- ,''`. Christian Hofstaedtler : :' : Debi