~ubuntu-branches/ubuntu/lucid/libopenid-ruby/lucid-updates

Viewing all changes in revision 6.

  • Committer: Package Import Robot
  • Author(s): Christian Kuersteiner
  • Date: 2013-06-20 15:51:01 UTC
  • Revision ID: package-import@ubuntu.com-20130620155101-eyzyve62fep9iir3
Tags: 2.1.7debian-1ubuntu0.1
* SECURITY UPDATE: XML denial of service attack (LP: #1190491)
  - debian/patches/CVE-2013-1812.patch: lib/openid/fetchers.rb,
    lib/openid/yadis/xrds.rb: limit fetching file size & disable XML entity
    expansion. Based on upstream patch.
  - CVE-2013-1812

expand all expand all

Show diffs side-by-side

added added

removed removed

Lines of Context: