Original released date: 31 Jan 2005
Last revised: 31 Jan 2005
Package: ruby
Summary: Two vulnerabilities discovered in Ruby
More information:
Ruby is an interpreted scripting language designed to allow quick and
easy object-oriented programming. It has many features to process text
files and to perform system management tasks (as in Perl). It is simple,
straight-forward, and extensible.
Two issues have been discovered in Ruby:
- CGI::Session's FileStore implementations store session information
insecurely
- The CGI module in Ruby allows remote attackers to cause a denial of
service (excessive CPU consumption due to an infinite loop) via a
malformed HTTP request
Impact:
The vulnerabilities may allow a local user to steal session information
and hijack sessions or allow a remote attacker to cause a denial of
service in the CGI module in Ruby.
Affected Products:
- Turbolinux 10 Server
- Turbolinux Home
- Turbolinux 10 F...
- Turbolinux 10 Desktop
- Turbolinux 8 Server
- Turbolinux 8 Workstation
- Turbolinux 7 Server
- Turbolinux 7 Workstation
Solution:
Please use the turbopkg (zabom) tool to apply the update.
---------------------------------------------
[Turbolinux 10 Server, Turbolinux 10 Desktop, Turbolinux 10 F...,
Turbolinux Home]
# turbopkg
or
# zabom -u ruby
[other]
# turbopkg
or
# zabom update ruby
---------------------------------------------
--------------------------------------------------------------------------
Revision History
31 Jan 2005 Initial release
--------------------------------------------------------------------------
Copyright(C) 2005 Turbolinux, Inc. All rights reserved.