Описание
ELSA-2008-0897: ruby security update (MODERATE)
[1.8.5-5.el5_2.5]
- Build with -fno-strict-aliasing.
[1.8.5-5.el5_2.4]
- security fixes. (#461590)
- CVE-2008-3655: multiple insufficient safe mode restrictions.
- CVE-2008-3656: WEBrick DoS vulnerability (CPU consumption).
- CVE-2008-3657: missing taintness checks in dl module.
- CVE-2008-3905: use of predictable source port and transaction id in DNS requests done by resolv.rb module.
- CVE-2008-3443: Memory allocation failure in Ruby regex engine (remotely exploitable DoS).
- CVE-2008-3790: DoS vulnerability in the REXML module.
Обновленные пакеты
Oracle Linux 5
Oracle Linux x86_64
ruby
1.8.5-5.el5_2.5
ruby-devel
1.8.5-5.el5_2.5
ruby-docs
1.8.5-5.el5_2.5
ruby-irb
1.8.5-5.el5_2.5
ruby-libs
1.8.5-5.el5_2.5
ruby-mode
1.8.5-5.el5_2.5
ruby-rdoc
1.8.5-5.el5_2.5
ruby-ri
1.8.5-5.el5_2.5
ruby-tcltk
1.8.5-5.el5_2.5
Oracle Linux i386
ruby
1.8.5-5.el5_2.5
ruby-devel
1.8.5-5.el5_2.5
ruby-docs
1.8.5-5.el5_2.5
ruby-irb
1.8.5-5.el5_2.5
ruby-libs
1.8.5-5.el5_2.5
ruby-mode
1.8.5-5.el5_2.5
ruby-rdoc
1.8.5-5.el5_2.5
ruby-ri
1.8.5-5.el5_2.5
ruby-tcltk
1.8.5-5.el5_2.5
Ссылки на источники
Связанные уязвимости
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации
Уязвимости операционной системы Debian GNU/Linux, позволяющие удаленному злоумышленнику нарушить доступность защищаемой информации
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFileHandler in WEBrick in Ruby 1.8.5 and earlier, 1.8.6 through 1.8.6-p286, 1.8.7 through 1.8.7-p71, and 1.9 through r18423 allows context-dependent attackers to cause a denial of service (CPU consumption) via a crafted HTTP request that is processed by a backtracking regular expression.