Bug #9685

psych-2.0.5 のバックポート

Added by Hiroshi SHIBATA 11 months ago. Updated 10 months ago.

[ruby-dev:48073]
Status:Closed
Priority:Normal
Assignee:-
ruby -v:ruby 2.2.0dev (2014-03-27 trunk 45452) [x86_64-darwin13] Backport:2.0.0: DONE, 2.1: DONE

Description

CVE-2014-2525 の修正を含んだ psych-2.0.5 のバックポートをお願いします。

ref. https://github.com/tenderlove/psych/pull/187
related commits. r45454, r45455

History

#1 Updated by Hiroshi SHIBATA 11 months ago

  • Status changed from Open to Closed

#2 Updated by Tomoyuki Chikanaga 10 months ago

  • Backport changed from 2.0.0: REQUIRED, 2.1: REQUIRED to 2.0.0: REQUIRED, 2.1: DONE

r45453, r45455 and r45577 were backported into ruby_2_1 at r45812.
See #9798

#3 Updated by Usaku NAKAMURA 10 months ago

  • Backport changed from 2.0.0: REQUIRED, 2.1: DONE to 2.0.0: DONE, 2.1: DONE

backported a part of r45453 into ruby_2_0_0.

I decided to update only libyaml and not psych itself.

Also available in: Atom PDF