LWN.net Logo

ruby: escape sequence injection

Package(s):ruby CVE #(s):CVE-2009-4492
Created:January 14, 2010 Updated:August 15, 2011
Description: From the Fedora alert:

A security vulnerability is found on WEBrick module in Ruby currently shipped on Fedora 11 that WEBrick lets attackers to inject malicious escape sequences to its logs, making it possible for dangerous control characters to be executed on a victim's terminal emulator.

Alerts:
CentOS CESA-2011:0908 2011-08-14
CentOS CESA-2011:0909 2011-06-30
Scientific Linux SL-ruby-20110628 2011-06-28
Scientific Linux SL-ruby-20110628 2011-06-28
Red Hat RHSA-2011:0909-01 2011-06-28
Red Hat RHSA-2011:0908-01 2011-06-28
Pardus 2010-19 2010-02-04
Mandriva MDVSA-2010:017 2010-01-19
Fedora FEDORA-2010-0530 2010-01-14
Gentoo 201001-09 2010-01-14
Fedora FEDORA-2010-0533 2010-01-14
Ubuntu USN-900-1 2010-02-16

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds