diff --git a/graphics/rubygem-dragonfly/Makefile b/graphics/rubygem-dragonfly/Makefile index 7d0695dfb0a7..b2fc403a0307 100644 --- a/graphics/rubygem-dragonfly/Makefile +++ b/graphics/rubygem-dragonfly/Makefile @@ -1,18 +1,17 @@ -# Ports collection makefile for: rubygem-dragonfly -# Date created: 13 January 2011 -# Whom: Jason Helfman -# +# Created by: Jason Helfman # $FreeBSD$ PORTNAME= dragonfly -PORTVERSION= 0.9.12 +PORTVERSION= 0.9.14 CATEGORIES= graphics rubygems MASTER_SITES= RG MAINTAINER= ruby@FreeBSD.org COMMENT= On-the-fly Rack-based image handling framework -RUN_DEPENDS+= rubygem-rack>=0:${PORTSDIR}/www/rubygem-rack +RUN_DEPENDS+= rubygem-rack>=0:${PORTSDIR}/www/rubygem-rack \ + rubygem-multi_json>=1.0:${PORTSDIR}/devel/rubygem-multi_json + USE_RUBY= yes USE_RUBYGEMS= yes diff --git a/graphics/rubygem-dragonfly/distinfo b/graphics/rubygem-dragonfly/distinfo index 49ef3971cb12..ec1218fc6deb 100644 --- a/graphics/rubygem-dragonfly/distinfo +++ b/graphics/rubygem-dragonfly/distinfo @@ -1,2 +1,2 @@ -SHA256 (rubygem/dragonfly-0.9.12.gem) = 52c3beec7e9be7560158b1a31126966a28b4ed74141caaef5d550936d6cf4851 -SIZE (rubygem/dragonfly-0.9.12.gem) = 444416 +SHA256 (rubygem/dragonfly-0.9.14.gem) = 6b364299b25aee6f5928dc6cb13677f27c892b0a090dc0a5b6d7ac465dfa1234 +SIZE (rubygem/dragonfly-0.9.14.gem) = 446976 diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index 48891aefe023..df5818daae8b 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -51,6 +51,37 @@ Note: Please add new entries to the beginning of this file. --> + + rubygem-dragonfly -- arbitrary code execution + + + rubygem18-dragonfly + rubygem19-dragonfly + rubygem20-dragonfly + 0.9.14 + + + + +

Mark Evans reports:

+
+

Unfortunately there is a security vulnerability in Dragonfly when + used with Rails which would potentially allow an attacker to run + arbitrary code on a host machine using carefully crafted + requests. +

+
+ +
+ + CVE-2013-1756 + + + 2013-02-19 + 2013-02-28 + +
+ linux-flashplugin -- multiple vulnerabilities