Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2011-0910

Опубликовано: 28 июн. 2011
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2011-0910: ruby security update (MODERATE)

[1.8.7.299-7.1]

  • Address CVE-2011-1004 'Symlink race condition by removing directory trees in fileutils module'
    • ruby-1.8.7-CVE-2011-1004.patch
  • Address CVE-2011-1005 'Untrusted codes able to modify arbitrary strings'
    • ruby-1.8.7-CVE-2011-1005.patch
  • Address CVE-2011-0188 'memory corruption in BigDecimal on 64bit platforms'
    • ruby-1.8.7-CVE-2011-0188.patch
  • Resolves: rhbz#709963

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

ruby

1.8.7.299-7.el6_1.1

ruby-devel

1.8.7.299-7.el6_1.1

ruby-docs

1.8.7.299-7.el6_1.1

ruby-irb

1.8.7.299-7.el6_1.1

ruby-libs

1.8.7.299-7.el6_1.1

ruby-rdoc

1.8.7.299-7.el6_1.1

ruby-ri

1.8.7.299-7.el6_1.1

ruby-static

1.8.7.299-7.el6_1.1

ruby-tcltk

1.8.7.299-7.el6_1.1

Oracle Linux i686

ruby

1.8.7.299-7.el6_1.1

ruby-devel

1.8.7.299-7.el6_1.1

ruby-docs

1.8.7.299-7.el6_1.1

ruby-irb

1.8.7.299-7.el6_1.1

ruby-libs

1.8.7.299-7.el6_1.1

ruby-rdoc

1.8.7.299-7.el6_1.1

ruby-ri

1.8.7.299-7.el6_1.1

ruby-static

1.8.7.299-7.el6_1.1

ruby-tcltk

1.8.7.299-7.el6_1.1

Связанные уязвимости

oracle-oval
около 14 лет назад

ELSA-2011-0909: ruby security update (MODERATE)

ubuntu
больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

redhat
больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

nvd
больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via the Exception#to_s method, as demonstrated by changing an intended pathname.

debian
больше 14 лет назад

The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through ...