--EXKGNeO8l0xGFBjy
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Good news everyone!  Rails version 3.0.13 has been released.

This release of Rails contains two important security fixes:

  * CVE-2012-2660 Ruby on Rails Active Record Unsafe Query Generation Risk
  * CVE-2012-2661 Ruby on Rails Active Record SQL Injection Vulnerability

It is suggested that all users upgrade immediately.  For more information a=
bout
these issues, please see the annoumcenents on the rubyonrails-security
mailing list:

  https://groups.google.com/group/rubyonrails-security

Specifically these announcements:

  https://groups.google.com/group/rubyonrails-security/browse_thread/thread=
/f1203e3376acec0f
  https://groups.google.com/group/rubyonrails-security/browse_thread/thread=
/7546a238e1962f59

Other changes for this release can be found in each component's CHANGELOG:

  https://github.com/rails/rails/blob/3-0-stable/actionmailer/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/actionpack/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/activemodel/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/activerecord/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/activesupport/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/railties/CHANGELOG

All changes can be found here:

  https://github.com/rails/rails/compare/v3.0.12...v3.0.13

I want to give a special thanks to Ben Murphy for responsibly reporting the=
 two
security issues that are fixed in this release.  Thank you very much!

<3<3<3

--=20
Aaron Patterson
http://tenderlovemaking.com/

--EXKGNeO8l0xGFBjy
Content-Type: application/pgp-signature

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (Darwin)

iQEcBAEBAgAGBQJPx7n5AAoJEJUxcLy0/6/G7FQIAJId+cD+nOPpi2w/j0Q3Eolc
lExicI7I7Eh7TfY3RpP1YEqvaawF//Am6bt0g58YAmJjhw8wv8danuDDuWFhldVh
MJ1YNz+jFcKRr6SKrJC2EvySBkb721OnZrLeDshELMOugofQKf+OyJVKge+kNpRM
wuZKQXmrjRuhMcm37u13cxTIeT+00FkYAebvm+/ZyBBu1Jv0O1kGgOk05keNRzyv
NWT9TuD9rfG5PFAPXrh6gIFkahHZhsvq62YNRaCKZdEdhpfNuLI4lhYBSGJTyYo0
mWNOS5+pBTC20aaQ3F8CgOZe2n/ecdFqlgjbPKeyOMhplxL8Va+eEP+oYcUT0mc=
=Tqiu
-----END PGP SIGNATURE-----

--EXKGNeO8l0xGFBjy--

Good news everyone!  Rails version 3.0.13 has been released.

This release of Rails contains two important security fixes:

  * CVE-2012-2660 Ruby on Rails Active Record Unsafe Query Generation Risk
  * CVE-2012-2661 Ruby on Rails Active Record SQL Injection Vulnerability

It is suggested that all users upgrade immediately.  For more information a=
bout
these issues, please see the annoumcenents on the rubyonrails-security
mailing list:

  https://groups.google.com/group/rubyonrails-security

Specifically these announcements:

  https://groups.google.com/group/rubyonrails-security/browse_thread/thread=
/f1203e3376acec0f
  https://groups.google.com/group/rubyonrails-security/browse_thread/thread=
/7546a238e1962f59

Other changes for this release can be found in each component's CHANGELOG:

  https://github.com/rails/rails/blob/3-0-stable/actionmailer/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/actionpack/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/activemodel/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/activerecord/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/activesupport/CHANGELOG
  https://github.com/rails/rails/blob/3-0-stable/railties/CHANGELOG

All changes can be found here:

  https://github.com/rails/rails/compare/v3.0.12...v3.0.13

I want to give a special thanks to Ben Murphy for responsibly reporting the=
 two
security issues that are fixed in this release.  Thank you very much!

<3<3<3

--=20
Aaron Patterson
http://tenderlovemaking.com/
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (Darwin)

iQEcBAEBAgAGBQJPx7n5AAoJEJUxcLy0/6/G7FQIAJId+cD+nOPpi2w/j0Q3Eolc
lExicI7I7Eh7TfY3RpP1YEqvaawF//Am6bt0g58YAmJjhw8wv8danuDDuWFhldVh
MJ1YNz+jFcKRr6SKrJC2EvySBkb721OnZrLeDshELMOugofQKf+OyJVKge+kNpRM
wuZKQXmrjRuhMcm37u13cxTIeT+00FkYAebvm+/ZyBBu1Jv0O1kGgOk05keNRzyv
NWT9TuD9rfG5PFAPXrh6gIFkahHZhsvq62YNRaCKZdEdhpfNuLI4lhYBSGJTyYo0
mWNOS5+pBTC20aaQ3F8CgOZe2n/ecdFqlgjbPKeyOMhplxL8Va+eEP+oYcUT0mc=
=Tqiu
-----END PGP SIGNATURE-----