LWN.net Logo

Mageia alert MGASA-2012-0294 (ruby)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2012-0294: ruby-1.8.7.p357-1.1.mga1 (1/core), ruby-1.8.7.p358-1.1.mga2 (2/core)
Date:  Sun, 14 Oct 2012 21:21:18 +0200
Message-ID:  <20121014192118.GA9855@valstar.mageia.org>
Archive-link:  Article, Thread

MGASA-2012-0294 Date: October 14th, 2012 Affected releases: 1, 2 Description: Updated ruby packages fix security vulnerabilities: Shugo Maedo and Vit Ondruch discovered that Ruby incorrectly allowed untainted strings to be modified in protective safe levels. An attacker could use this flaw to bypass intended access restrictions. (CVE-2012-4466, CVE-2012-4481) Updated Packages: Mageia 1: ruby-1.8.7.p357-1.1.mga1 ruby-doc-1.8.7.p357-1.1.mga1 ruby-devel-1.8.7.p357-1.1.mga1 ruby-tk-1.8.7.p357-1.1.mga1 Mageia 2: ruby-1.8.7.p358-1.1.mga2 ruby-doc-1.8.7.p358-1.1.mga2 ruby-devel-1.8.7.p358-1.1.mga2 ruby-tk-1.8.7.p358-1.1.mga2 References: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4466 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4481 http://www.ubuntu.com/usn/usn-1603-1/ https://bugs.mageia.org/show_bug.cgi?id=7769 https://wiki.mageia.org/en/Support/Advisories/MGASA-2012-...


(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds