|
|
Subscribe / Log in / New account

Debian-LTS alert DLA-299-1 (ruby1.8)

From:  Santiago Ruano Rincón <santiagorr@riseup.net>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 299-1] ruby1.8 security update
Date:  Wed, 26 Aug 2015 14:22:01 +0200
Message-ID:  <20150826122201.GA16933@nomada>

Package : ruby1.8 Version : 1.8.7.302-2squeeze5 CVE ID : CVE-2009-5147 "sheepman" fixed a vulnerability in Ruby 1.8: DL::dlopen could open a library with tainted name even if $SAFE > 0. For Debian 6 “Squeeze”, this issue has been fixed in ruby1.8 1.8.7.302-2squeeze5.


to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds