-
Tue Aug 23 2016 Pavel Valena <pvalena@redhat.com> - 1:3.2.8-20
- Fix for CVE-2016-6316 cross-site scripting flaw in Action View
Resolves: rhbz#1365008
-
Tue Mar 08 2016 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-16
- Update the CVE-2016-2097 to the latest upstream version.
Related: CVE-2016-2097
- Update the CVE-2016-2098 patch to the latest upstream version.
Related: CVE-2016-2098
-
Wed Feb 24 2016 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-15
- Fix Directory traversal and information leak in Action View.
Resolves: CVE-2016-2097
- Fix code injection vulnerability.
Resolves: CVE-2016-2098
-
Tue Feb 23 2016 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-14
- Fix Timing attack vulnerability in Action Controller.
Resolves: CVE-2015-7576
- Fix Possible Object Leak and Denial of Service attack.
Resolves: CVE-2016-0751
- Fix Possible Information Leak Vulnerability.
Resolves: CVE-2016-0752
-
Wed May 14 2014 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-13
- Fixes for CVE-2014-0130
- Resolves: rhbz#1096086
-
Thu Feb 20 2014 Josef Stribny <jstribny@redhat.com> - 1:3.2.8-11
- Fix for CVE-2014-0082
- Resolves: rhbz#1065891
-
Tue Feb 18 2014 Josef Stribny <jstribny@redhat.com> - 1:3.2.8-10
- Fix for CVE-2014-0081
- Resolves: rhbz#1065891
-
Mon Feb 17 2014 Josef Stribny <jstribny@redhat.com> - 1:3.2.8-9
- Depend on scldevel(v8) virtual provide
- Resolves: rhbz#1065887
-
Tue Feb 11 2014 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-8
- Fix regression introduced by CVE-2013-6415.
- Resolves: rhbz#1038194
-
Tue Dec 03 2013 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-7
- Fix i18n missing translation XSS.
* rubygem-actionpack-3.2.16-CVE-2013-4491-Stop-using-i18ns-built-in-HTML-error-handling.patch
- Resolves: CVE-2013-4491
- Fix Action View DoS.
* rubygem-actionpack-3.2.16-CVE-2013-6414-Only-use-valid-mime-type-symbols-as-cache-keys.patch
- Resolves: CVE-2013-6414
- Fix number_to_currency XSS.
* rubygem-actionpack-3.2.16-CVE-2013-6415-Escape-the-unit-value-provided-to-number_to_currency.patch
- Resolves: CVE-2013-6415
- Fix unsafe query generation risk in Ruby on Rails (incomplete fix for
CVE-2013-0155) (CVE-2013-6417).
* rubygem-actionpack-3.2.16-CVE-2013-6417-Deep-Munge-the-parameters-for-GET-and-POST.patch
- Resolves: CVE-2013-6417
-
Thu Nov 28 2013 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-6
- Build against v8314 SCL.
-
Mon Mar 18 2013 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-5
- Updated patch for CVE-2013-1857 by upstream.
-
Fri Mar 15 2013 Vít Ondruch <vondruch@redhat.com> - 1:3.2.8-4
- Fix for CVE-2013-1855 and CVE-2013-1857.
-
Mon Jan 14 2013 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.2.8-3
- Fix for CVE-2013-0155.
-
Thu Jan 10 2013 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.2.8-2
- Fix for CVE-2013-0156.
-
Tue Sep 18 2012 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.2.8-1
- Updated to ActionPack 3.2.8.
-
Fri Jul 27 2012 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.2.6-4
- Fixed the require in the -doc subpackage.
-
Thu Jul 26 2012 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.2.6-3
- Import from Fedora again.
- Specfile cleanup
-
Tue Jul 24 2012 Vít Ondruch <vondruch@redhat.com> - 1:3.2.6-2
- Fixed missing epoch in -doc subpackage.
-
Mon Jul 23 2012 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.2.6-1
- Updated to the ActionPack 3.2.6.
- Remove Rake dependency.
- Introduce -doc subpackage.
- Relax sprockets dependency.
-
Sat Jul 21 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:3.0.15-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
-
Fri Jun 15 2012 Vít Ondruch <vondruch@redhat.com> - 1:3.0.15-1
- Updated to the ActionPack 3.0.15.
-
Fri Jun 01 2012 Vít Ondruch <vondruch@redhat.com> - 1:3.0.13-1
- Updated to the ActionPack 3.0.13.
-
Fri Mar 16 2012 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.0.11-3
- The CVE patches names now contain the CVE id.
-
Tue Mar 06 2012 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.0.11-2
- Fix for CVE-2012-1098.
- Fix for CVE-2012-1099.
-
Tue Jan 31 2012 Bohuslav Kabrda <bkabrda@redhat.com> - 1:3.0.11-1
- Rebuilt for Ruby 1.9.3.
- Updated to ActionPack 3.0.11.
-
Sat Jan 14 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:3.0.10-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_17_Mass_Rebuild
-
Mon Aug 22 2011 Vít Ondruch <vondruch@redhat.com> - 1:3.0.10-1
- Update to ActionPack 3.0.10
-
Mon Jul 04 2011 Vít Ondruch <vondruch@redhat.com> - 1:3.0.9-1
- Update to ActionPack 3.0.9
-
Thu Jun 16 2011 Mo Morsi <mmorsi@redhat.com> - 1:3.0.5-3
- Include fix for CVE-2011-2197
-
Fri Jun 03 2011 Vít Ondruch <vondruch@redhat.com> - 1:3.0.5-2
- Removed regin and multimap dependencies. They were added into rack-mount
where they actually belongs.
-
Fri Mar 25 2011 Vít Ondruch <vondruch@redhat.com> - 1:3.0.5-1
- Updated to ActionPack 3.0.5
-
Wed Feb 16 2011 Vít Ondruch <vondruch@redhat.com> - 1:3.0.3-4
- Relaxed erubis dependency
- Fixed build compatibility with RubyGems 1.5
-
Wed Feb 09 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:3.0.3-3
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
-
Mon Feb 07 2011 Mohammed Morsi <mmorsi@redhat.com> - 1:3.0.3-2
- changelog fixes
-
Mon Jan 10 2011 Mohammed Morsi <mmorsi@redhat.com> - 1:3.0.3-1
- Update to rails 3
-
Thu Aug 12 2010 Mohammed Morsi <mmorsi@redhat.com> - 1:2.3.8-2
- Bumped actionpack rack dependency to version 1.1.0
-
Mon Aug 09 2010 Mohammed Morsi <mmorsi@redhat.com> - 1:2.3.8-1
- Update to 2.3.8
-
Mon May 17 2010 Mamoru Tasaka <mtasaka@ioa.s.u-tokyo.ac.jp> - 1:2.3.5-2
- Set TMPDIR environment at %check to make it sure all files created
during rpmbuild are cleaned up
-
Thu Jan 28 2010 Mamoru Tasaka <mtasaka@ioa.s.u-tokyo.ac.jp> - 1:2.3.5-1
- Update to 2.3.5
-
Fri Jan 08 2010 Mamoru Tasaka <mtasaka@ioa.s.u-tokyo.ac.jp> - 1:2.3.4-4
- Workaround patch to fix for rack 1.1.0 dependency (bug 552972)
-
Thu Dec 10 2009 David Lutterkort <lutter@redhat.com> - 1:2.3.4-3
- Patch for CVE-2009-4214 (bz 542786)
-
Wed Oct 07 2009 David Lutterkort <lutter@redhat.com> - 1:2.3.4-2
- Bump Epoch to ensure upgrade path from F-11
-
Sun Sep 20 2009 Mamoru Tasaka <mtasaka@ioa.s.u-tokyo.ac.jp> - 2.3.4-1
- Update to 2.3.4 (bug 520843, CVE-2009-3009)
- Fix tests
-
Sun Aug 02 2009 Mamoru Tasaka <mtasaka@ioa.s.u-tokyo.ac.jp> - 2.3.3-1
- 2.3.3
- Enable test (some tests fail, please someone investigate!!)
-
Sun Jul 26 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.3.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
-
Mon Mar 16 2009 Jeroen van Meeuwen <j.van.meeuwen@ogd.nl> - 2.3.2-1
- New upstream version
-
Wed Feb 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.2.2-2
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
-
Tue Dec 23 2008 David Lutterkort <lutter@redhat.com> - 2.2.2-1
- New version
-
Tue Sep 16 2008 David Lutterkort <dlutter@redhat.com> - 2.1.1-1
- New version (fixes CVE-2008-4094)
-
Thu Jul 31 2008 Michael Stahnke <stahnma@fedoraproject.org> - 2.1.0-1
- New Upstream
-
Tue Apr 08 2008 David Lutterkort <dlutter@redhat.com> - 2.0.2-2
- Fix dependency
-
Mon Apr 07 2008 David Lutterkort <dlutter@redhat.com> - 2.0.2-1
- New version
-
Mon Dec 10 2007 David Lutterkort <dlutter@redhat.com> - 2.0.1-1
- New version
-
Thu Nov 29 2007 David Lutterkort <dlutter@redhat.com> - 1.13.6-1
- New version
-
Wed Nov 14 2007 David Lutterkort <dlutter@redhat.com> - 1.13.5-2
- Fix buildroot; mark docs in geminstdir cleanly
-
Tue Oct 30 2007 David Lutterkort <dlutter@redhat.com> - 1.13.5-1
- Initial package