Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2013-0612

Опубликовано: 07 мар. 2013
Источник: oracle-oval
Платформа: Oracle Linux 6

Описание

ELSA-2013-0612: ruby security update (MODERATE)

[1.8.7.352-10]

  • escaping vulnerability about Exception#to_s / NameError#to_s
  • ruby-1.8.7-p371-CVE-2012-4481.patch
  • Related: rhbz#915379

[1.8.7.352-9]

[1.8.7.352-8]

  • Addresses entity expansion DoS vulnerability in REXML.
    • ruby-2.0.0-entity-expansion-DoS-vulnerability-in-REXML.patch
  • Resolves: rhbz#915379

Обновленные пакеты

Oracle Linux 6

Oracle Linux x86_64

ruby

1.8.7.352-10.el6_4

ruby-devel

1.8.7.352-10.el6_4

ruby-docs

1.8.7.352-10.el6_4

ruby-irb

1.8.7.352-10.el6_4

ruby-libs

1.8.7.352-10.el6_4

ruby-rdoc

1.8.7.352-10.el6_4

ruby-ri

1.8.7.352-10.el6_4

ruby-static

1.8.7.352-10.el6_4

ruby-tcltk

1.8.7.352-10.el6_4

Oracle Linux i686

ruby

1.8.7.352-10.el6_4

ruby-devel

1.8.7.352-10.el6_4

ruby-docs

1.8.7.352-10.el6_4

ruby-irb

1.8.7.352-10.el6_4

ruby-libs

1.8.7.352-10.el6_4

ruby-rdoc

1.8.7.352-10.el6_4

ruby-ri

1.8.7.352-10.el6_4

ruby-static

1.8.7.352-10.el6_4

ruby-tcltk

1.8.7.352-10.el6_4

Связанные CVE

Связанные уязвимости

ubuntu
больше 12 лет назад

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.

redhat
больше 12 лет назад

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.

nvd
больше 12 лет назад

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an XML Entity Expansion (XEE) attack.

debian
больше 12 лет назад

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows ...

ubuntu
больше 12 лет назад

The safe-level feature in Ruby 1.8.7 allows context-dependent attackers to modify strings via the NameError#to_s method when operating on Ruby objects. NOTE: this issue is due to an incomplete fix for CVE-2011-1005.