Forum: Ruby on Rails Security fix CVE-2012-5664 exists in rails 2.3.15

Posted by Ariel Tal (Guest)
on 2013-02-24 22:35
(Received via mailing list)
Hello,
I was looking to migrate the patch described in this 
link<https://groups.google.com/forum/?fromgroups=#!topi...
 (
https://groups.google.com/forum/?fromgroups=#!topi...)
to the rails 2.3 branch, but when doing so realized that it's already 
there.

I couldn't find anything about this in the release notes, I was 
wondering
if the link above might be incomplete? If it's not a mistake, is it
possible to add a note about it somewhere?

Thanks,
Ariel
Posted by Rick Lloyd (ricklloyd)
on 2013-02-25 00:36
(Received via mailing list)
The original announcement of Rails 3.2.10...  was posted on *January 2*.
The current version is at 3.2.12.  It's quite possible the 2.3 branch 
has
also advanced.
Rick
Posted by Ariel Tal (Guest)
on 2013-02-25 12:55
(Received via mailing list)
I was looking for something official that would indicate that.
Thanks,
Ariel
Posted by Frederick Cheung (Guest)
on 2013-02-25 13:46
(Received via mailing list)
The change log for rails 2.3.15
( https://github.com/rails/rails/compare/v2.3.14...v2.3.15) shows that a
fix for cve-2012-5664 was in that version

Fred
Posted by Ariel Tal (Guest)
on 2013-02-25 14:31
(Received via mailing list)
Thank you! Just what I was looking for!
Posted by Walter Davis (walterdavis)
on 2013-02-25 14:39
(Received via mailing list)
Please log in before posting. Registration is free and takes only a minute.
Existing account (Switch to SSL-encrypted connection)
NEW: Do you have a Google/GoogleMail or Yahoo account? No registration required!
Log in with Google account | Log in with Yahoo account
No account? Register here.