You are here
Home > Preporuke > Sigurnosni nedostaci programskog paketa rubygem

Sigurnosni nedostaci programskog paketa rubygem

  • Detalji os-a: WN7
  • Važnost: IMP
  • Operativni sustavi: L
  • Kategorije: LFE

——————————————————————————–
Fedora Update Notification
FEDORA-2014-3232
2014-02-28 17:42:26
——————————————————————————–

Name : rubygem-actionpack
Product : Fedora 19
Version : 3.2.13
Release : 5.fc19
URL : http://www.rubyonrails.org
Summary : Web-flow and rendering framework putting the VC in MVC
Description :
Eases web-request routing, handling, and response as a half-way front,
half-way page controller. Implemented with specific emphasis on enabling easy
unit/integration testing that doesn’t require a browser.

——————————————————————————–
Update Information:

This fixes Ruby on Rails 3.2.17 security issues:

– CVE-2014-0081
– CVE-2014-0082

Includes security patches for:

– CVE-2013-6417 – Incomplete fix to CVE-2013-0155 (Unsafe Query Generation Risk)
– CVE-2013-4491 – Reflective XSS Vulnerability in Ruby on Rails
– CVE-2013-6415 – XSS Vulnerability in number_to_currency
– CVE-2013-6414 – Denial of Service Vulnerability in Action View
——————————————————————————–
ChangeLog:

* Wed Feb 26 2014 Josef Stribny <jstribny@redhat.com> – 1:3.2.13-5
– Fix CVE-2014-0081 and CVE-2014-0082
* Wed Jan 15 2014 Vít Ondruch <vondruch@redhat.com> – 1:3.2.13-4
– Avoid potential format string vulnerabilities where user-provided
data is interpolated into the log message before String#% is called.
(CVE-2013-4389).
* Mon Dec 16 2013 Josef Stribny <jstribny@redhat.com> – 1:3.2.13-3
– Fixes for CVE-2013-6417, CVE-2013-4491, CVE-2013-6415, CVE-2013-6414
——————————————————————————–
References:

[ 1 ] Bug #1065538 – CVE-2014-0082 rubygem-actionpack: Action View string handling denial of service
https://bugzilla.redhat.com/show_bug.cgi?id=1065538
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update rubygem-actionpack’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-3169
2014-02-28 17:39:41
——————————————————————————–

Name : rubygem-actionpack
Product : Fedora 20
Version : 4.0.0
Release : 3.fc20
URL : http://www.rubyonrails.org
Summary : Web-flow and rendering framework putting the VC in MVC
Description :
Eases web-request routing, handling, and response as a half-way front,
half-way page controller. Implemented with specific emphasis on enabling easy
unit/integration testing that doesn’t require a browser.

——————————————————————————–
Update Information:

This fixes Ruby on Rails 4.0.3 security CVEs:

– CVE-2014-0080
– CVE-2014-0081

——————————————————————————–
ChangeLog:

* Wed Feb 26 2014 Josef Stribny <jstribny@redhat.com> – 1:4.0.0-3
– Fix CVE-2014-0081
* Mon Dec 16 2013 Josef Stribny <jstribny@redhat.com> – 1:4.0.0-2
– Fixes for CVE-2013-6414, CVE-2013-6415, CVE-2013-6416, CVE-2013-6417, CVE-2013-4491
——————————————————————————–
References:

[ 1 ] Bug #1065520 – CVE-2014-0081 rubygem-actionpack: number_to_currency, number_to_percentage and number_to_human XSS vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=1065520
[ 2 ] Bug #1065517 – CVE-2014-0080 rubygem-activerecord: PostgreSQL array data injection vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=1065517
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update rubygem-actionpack’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

——————————————————————————–
Fedora Update Notification
FEDORA-2014-3169
2014-02-28 17:39:41
——————————————————————————–

Name : rubygem-activerecord
Product : Fedora 20
Version : 4.0.0
Release : 2.fc20
URL : http://www.rubyonrails.org
Summary : Implements the ActiveRecord pattern for ORM
Description :
Implements the ActiveRecord pattern (Fowler, PoEAA) for ORM. It ties database
tables and classes together for business objects, like Customer or
Subscription, that can find, save, and destroy themselves without resorting to
manual SQL.

——————————————————————————–
Update Information:

This fixes Ruby on Rails 4.0.3 security CVEs:

– CVE-2014-0080
– CVE-2014-0081

——————————————————————————–
ChangeLog:

* Wed Feb 26 2014 Josef Stribny <jstribny@redhat.com> – 1:4.0.0-2
– Fix CVE-2014-0080: PostgreSQL array data injection vulnerability
– Fix SQLite tests
——————————————————————————–
References:

[ 1 ] Bug #1065520 – CVE-2014-0081 rubygem-actionpack: number_to_currency, number_to_percentage and number_to_human XSS vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=1065520
[ 2 ] Bug #1065517 – CVE-2014-0080 rubygem-activerecord: PostgreSQL array data injection vulnerability
https://bugzilla.redhat.com/show_bug.cgi?id=1065517
——————————————————————————–

This update can be installed with the “yum” update program. Use
su -c ‘yum update rubygem-activerecord’ at the command line.
For more information, refer to “Managing Software with yum”,
available at http://docs.fedoraproject.org/yum/.

All packages are signed with the Fedora Project GPG key. More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/keys
——————————————————————————–
_______________________________________________
package-announce mailing list
package-announce@lists.fedoraproject.org
https://admin.fedoraproject.org/mailman/listinfo/package-announce

AutorMarko Stanec
Cert idNCERT-REF-2014-03-0011-ADV
CveCERT-CVE-DUMMY
ID izvornikaCERT-ORIGID-DUMMY
ProizvodCERT-DUMMY-PRODUCT
Izvorhttp://www.adobe.com/
Top
More in Preporuke
Sigurnosni nedostaci u jezgri operacijskog sustava

Otkriveni su sigurnosni nedostaci u jezgri operacijskog sustava Fedora. Otkriveni nedostaci potencijalnim napadačima omogućuju izvršavanje proizvoljnog programskog koda ili izvođenje...

Close