LWN.net Logo

rubygem-actionpack: strip_tags function weakness

Package(s):rubygem-actionpack CVE #(s):CVE-2009-4214
Created:December 10, 2009 Updated:September 5, 2011
Description: From the Fedora bug report:

There is a weakness in the strip_tags function in ruby on rails. Due to a bug in the parsing code inside HTML::Tokenizer regarding non-printable ascii characters, an attacker can include values which certain browsers will then evaluate.

Alerts:
Debian DSA-2301-1 2011-09-05
Debian DSA-2260-1 2011-06-14
SuSE SUSE-SR:2010:006 2010-03-15
Gentoo 200912-02 2009-12-20
Fedora FEDORA-2009-13361 2009-12-18
Fedora FEDORA-2009-13393 2009-12-18
Fedora FEDORA-2009-12966 2009-12-10
SuSE SUSE-SR:2010:005 2010-02-23
Debian DSA-2392-1 2012-01-23

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds