Summary: | www/rubygem-passenger: update to 5.0.22 (CVE-2015-7519) | ||
---|---|---|---|
Product: | Ports & Packages | Reporter: | Jason Unovitch <junovitch> |
Component: | Individual Port(s) | Assignee: | Sergey A. Osokin <osa> |
Status: | Closed FIXED | ||
Severity: | Affects Some People | CC: | ports-secteam |
Priority: | --- | Keywords: | needs-patch, security |
Version: | Latest | Flags: | bugzilla:
maintainer-feedback?
(osa) junovitch: merge-quarterly? |
Hardware: | Any | ||
OS: | Any | ||
URL: | https://blog.phusion.nl/2015/12/07/cve-2015-7519/ |
Description
Jason Unovitch
2015-12-07 23:21:46 UTC
A commit references this bug: Author: junovitch Date: Mon Dec 7 23:22:25 UTC 2015 New revision: 403243 URL: https://svnweb.freebsd.org/changeset/ports/403243 Log: Document client controlled header overwriting in Phusion Passenger PR: 205104 Security: CVE-2015-7519 Security: https://vuxml.FreeBSD.org/freebsd/84fdd1bb-9d37-11e5-8f5c-002590263bf5.html Changes: head/security/vuxml/vuln.xml Also see: http://www.openwall.com/lists/oss-security/2015/12/07/1 http://www.openwall.com/lists/oss-security/2015/12/07/2 vuxml done, needs port update + mfh A commit references this bug: Author: osa Date: Tue Dec 8 23:08:12 UTC 2015 New revision: 403349 URL: https://svnweb.freebsd.org/changeset/ports/403349 Log: Security update from 5.0.21 to 5.0.22: o) www/rubygem-passenger; o) third-party passenger modules for www/nginx and www/nginx-devel. Please note: third-party passenger module is disabled by default for www/nginx and www/nginx-devel ports. Security: CVE-2015-7519 PR: 205104 Changes: head/www/nginx/Makefile head/www/nginx/distinfo head/www/nginx/files/extra-patch-passenger-build-nginx.rb head/www/nginx-devel/Makefile head/www/nginx-devel/distinfo head/www/nginx-devel/files/extra-patch-passenger-build-nginx.rb head/www/rubygem-passenger/Makefile head/www/rubygem-passenger/distinfo A commit references this bug: Author: osa Date: Wed Dec 9 12:06:50 UTC 2015 New revision: 403377 URL: https://svnweb.freebsd.org/changeset/ports/403377 Log: Security update to 5.0.22: o) www/rubygem-passenger; o) third-party passenger modules for www/nginx and www/nginx-devel. Please note: third-party passenger module is disabled by default for www/nginx and www/nginx-devel ports. Security: CVE-2015-7519 PR: 205104 Approved by: ports-secteam Changes: branches/2015Q4/www/nginx/Makefile branches/2015Q4/www/nginx/distinfo branches/2015Q4/www/nginx/files/extra-patch-passenger-build-nginx.rb branches/2015Q4/www/nginx-devel/Makefile branches/2015Q4/www/nginx-devel/distinfo branches/2015Q4/www/nginx-devel/files/extra-patch-passenger-build-nginx.rb branches/2015Q4/www/rubygem-passenger/Makefile branches/2015Q4/www/rubygem-passenger/distinfo |