Description: | Description:
The remote host is missing an update to ruby announced via advisory FEDORA-2008-8736.
Update Information:
Update to new upstream release fixing multiple security issues detailed in the upstream advisories.
ChangeLog:
* Wed Oct 8 2008 Akira TAGOH - 1.8.6.287-2 - CVE-2008-3790: DoS vulnerability in the REXML module. * Sat Aug 23 2008 Akira TAGOH - 1.8.6.287-1 - New upstream release. - Security fixes. - CVE-2008-3655: Ruby does not properly restrict access to critical variables and methods at various safe levels. - CVE-2008-3656: DoS vulnerability in WEBrick. - CVE-2008-3657: Lack of taintness check in dl. - CVE-2008-1447: DNS spoofing vulnerability in resolv.rb. - CVE-2008-3443: Memory allocation failure in Ruby regex engine. - Remove the unnecessary backported patches.
References:
[ 1 ] Bug #458948 - CVE-2008-3655 ruby: multiple insufficient safe mode restrictions https://bugzilla.redhat.com/show_bug.cgi?id=458948 [ 2 ] Bug #458966 - CVE-2008-3657 ruby: missing taintness checks in dl module https://bugzilla.redhat.com/show_bug.cgi?id=458966 [ 3 ] Bug #461495 - CVE-2008-3905 ruby: use of predictable source port and transaction id in DNS requests done by resolv.rb module https://bugzilla.redhat.com/show_bug.cgi?id=461495 [ 4 ] Bug #459266 - CVE-2008-3443 ruby: Memory allocation failure in Ruby regex engine (remotely exploitable DoS) https://bugzilla.redhat.com/show_bug.cgi?id=459266 [ 5 ] Bug #458953 - CVE-2008-3656 ruby: WEBrick DoS vulnerability (CPU consumption) https://bugzilla.redhat.com/show_bug.cgi?id=458953 [ 6 ] Bug #460134 - CVE-2008-3790 ruby: DoS vulnerability in the REXML module https://bugzilla.redhat.com/show_bug.cgi?id=460134
Solution: Apply the appropriate updates.
This update can be installed with the yum update program. Use su -c 'yum update ruby' at the command line. For more information, refer to Managing Software with yum, available at http://docs.fedoraproject.org/yum/.
http://www.securityspace.com/smysecure/catid.html?in=FEDORA-2008-8736
Risk factor : Critical
CVSS Score: 10.0
|