|Category:||Red Hat Local Security Checks|
|Title:||RedHat Update for ruby RHSA-2013:0129-01|
|Summary:||The remote host is missing an update for the 'ruby'; package(s) announced via the referenced advisory.|
The remote host is missing an update for the 'ruby'
package(s) announced via the referenced advisory.
Ruby is an extensible, interpreted, object-oriented, scripting language. It
has features to process text files and to do system management tasks.
It was found that certain methods did not sanitize file names before
passing them to lower layer routines in Ruby. If a Ruby application created
files with names based on untrusted input, it could result in the creation
of files with different names than expected. (CVE-2012-4522)
It was found that the RHSA-2011:0909 update did not correctly fix the
CVE-2011-1005 issue, a flaw in the method for translating an exception
message into a string in the Exception class. A remote attacker could use
this flaw to bypass safe level 4 restrictions, allowing untrusted (tainted)
code to modify arbitrary, trusted (untainted) strings, which safe level 4
restrictions would otherwise prevent. (CVE-2012-4481)
The CVE-2012-4481 issue was discovered by Vit Ondruch of Red Hat.
This update also fixes the following bug:
* Prior to this update, the 'rb_syck_mktime' option could, under certain
circumstances, terminate with a segmentation fault when installing
libraries with certain gems. This update modifies the underlying code so
that Ruby gems can be installed as expected. (BZ#834381)
All users of Ruby are advised to upgrade to these updated packages, which
contain backported patches to resolve these issues.
ruby on Red Hat Enterprise Linux (v. 5 server)
Please Install the Updated Packages.
Common Vulnerability Exposure (CVE) ID: CVE-2012-4481|
RedHat Security Advisories: RHSA-2013:0129
RedHat Security Advisories: RHSA-2013:0612
Common Vulnerability Exposure (CVE) ID: CVE-2012-4522
Common Vulnerability Exposure (CVE) ID: CVE-2011-1005
BugTraq ID: 46458
|Copyright||Copyright (c) 2013 Greenbone Networks GmbH|
|This is only one of 99761 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.