Processed: Re: Bug#913005: ruby-rack: CVE-2018-16471: Possible XSS vulnerability in Rack

2018-11-20 Thread Debian Bug Tracking System
Processing commands for cont...@bugs.debian.org: > block 913005 by 914184 Bug #913005 [src:ruby-rack] ruby-rack: CVE-2018-16471: Possible XSS vulnerability in Rack 913005 was not blocked by any bugs. 913005 was not blocking any bugs. Added blocking bug(s) of 913005: 914184 > thanks Stopping proce

Bug#913005: ruby-rack: CVE-2018-16471: Possible XSS vulnerability in Rack

2018-11-20 Thread Chris Lamb
block 913005 by 914184 thanks Hi Salvatore, > I think those will be no-dsa and can be adressed via a point release Thanks, filed as: #914184. Regards, -- ,''`. : :' : Chris Lamb `. `'` la...@debian.org / chris-lamb.co.uk `-

Bug#913005: ruby-rack: CVE-2018-16471: Possible XSS vulnerability in Rack

2018-11-19 Thread Salvatore Bonaccorso
Hi Chris, On Mon, Nov 19, 2018 at 03:17:27AM -0500, Chris Lamb wrote: > Chris Lamb wrote: > > > Security team, like ruby-i18n, I would be more than happy to prepare > > and upload a stable security upload of this package when addressing > > it in jessie LTS. > […] > > Ruby team, again, I could ea

Bug#913005: ruby-rack: CVE-2018-16471: Possible XSS vulnerability in Rack

2018-11-19 Thread Chris Lamb
Chris Lamb wrote: > Security team, like ruby-i18n, I would be more than happy to prepare > and upload a stable security upload of this package when addressing > it in jessie LTS. […] > Ruby team, again, I could easily upload to sid at the same time. Let > me know here too. Gentle ping on the abov

Bug#913005: ruby-rack: CVE-2018-16471: Possible XSS vulnerability in Rack

2018-11-16 Thread Chris Lamb
Hi Salvatore et al., > Source: ruby-rack […] > CVE-2018-16471[0]: > Possible XSS vulnerability in Rack Security team, like ruby-i18n, I would be more than happy to prepare and upload a stable security upload of this package when addressing it in jessie LTS. Please let me know and I will come bac

Bug#913005: ruby-rack: CVE-2018-16471: Possible XSS vulnerability in Rack

2018-11-05 Thread Salvatore Bonaccorso
Source: ruby-rack Version: 1.6.4-4 Severity: grave Tags: patch security upstream Hi, The following vulnerability was published for ruby-rack. CVE-2018-16471[0]: Possible XSS vulnerability in Rack If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exp