BugTraq
[ MDVSA-2013:200 ] ruby Jul 26 2013 11:45AM
security mandriva com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2013:200
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : ruby
Date : July 26, 2013
Affected: Enterprise Server 5.0
_______________________________________________________________________

Problem Description:

Multiple vulnerabilities has been discovered and corrected in ruby:

The safe-level feature in Ruby 1.8.7 allows context-dependent attackers
to modify strings via the NameError#to_s method when operating on
Ruby objects. NOTE: this issue is due to an incomplete fix for
CVE-2011-1005 (CVE-2012-4481).

lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows
remote attackers to cause a denial of service (memory consumption and
crash) via crafted text nodes in an XML document, aka an XML Entity
Expansion (XEE) attack (CVE-2013-1821).

A flaw was found in Ruby's SSL client's hostname identity check
when handling certificates that contain hostnames with NULL
bytes. An attacker could potentially exploit this flaw to conduct
man-in-the-middle attacks to spoof SSL servers. Note that to exploit
this issue, an attacker would need to obtain a carefully-crafted
certificate signed by an authority that the client trusts
(CVE-2013-4073).

The updated packages have been patched to correct these issues.
_______________________________________________________________________

References:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4481
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-1821
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4073
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=863484
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=914716
http://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=979251
_______________________________________________________________________

Updated Packages:

Mandriva Enterprise Server 5:
54efd9d04ac7a92a38c9a531c0a5b956 mes5/i586/ruby-1.8.7-7p72.6mdvmes5.2.i586.rpm
6ca399ef73a5df70b24e8a54bc7e9184 mes5/i586/ruby-devel-1.8.7-7p72.6mdvmes5.2.i586.rpm
4e6ceeba8349c5ed2d9965dc9e7dca33 mes5/i586/ruby-doc-1.8.7-7p72.6mdvmes5.2.i586.rpm
cca93669e5f564c35d04d3427aa9b0bd mes5/i586/ruby-tk-1.8.7-7p72.6mdvmes5.2.i586.rpm
01677fdc63909deddc5584aab63d6b9a mes5/SRPMS/ruby-1.8.7-7p72.6mdvmes5.2.src.rpm

Mandriva Enterprise Server 5/X86_64:
c25ab3890d672abcdf3415e38f0ccfa9 mes5/x86_64/ruby-1.8.7-7p72.6mdvmes5.2.x86_64.rpm
1dbfd59b83e2d53382d3f5ebb524e942 mes5/x86_64/ruby-devel-1.8.7-7p72.6mdvmes5.2.x86_64.rpm
1eb316b715f155b09dcf0e75791be3e0 mes5/x86_64/ruby-doc-1.8.7-7p72.6mdvmes5.2.x86_64.rpm
091949b18bf3b6963224991677996f24 mes5/x86_64/ruby-tk-1.8.7-7p72.6mdvmes5.2.x86_64.rpm
01677fdc63909deddc5584aab63d6b9a mes5/SRPMS/ruby-1.8.7-7p72.6mdvmes5.2.src.rpm
_______________________________________________________________________

To upgrade automatically use MandrivaUpdate or urpmi. The verification
of md5 checksums and GPG signatures is performed automatically for you.

All packages are signed by Mandriva for security. You can obtain the
GPG public key of the Mandriva Security Team by executing:

gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

You can view other update advisories for Mandriva Linux at:

http://www.mandriva.com/en/support/security/advisories/

If you want to report vulnerabilities, please contact

security_(at)_mandriva.com
_______________________________________________________________________

Type Bits/KeyID Date User ID
pub 1024D/22458A98 2000-07-10 Mandriva Security Team
<security*mandriva.com>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.12 (GNU/Linux)

iD8DBQFR8jXZmqjQ0CJFipgRAmUMAJ9K8EET6TW7apveKan1ycCDGbfD2ACgg+oo
7vJpEOIBze8SI/CLNyUPc/I=
=sH+9
-----END PGP SIGNATURE-----

[ reply ]


 

Privacy Statement
Copyright 2010, SecurityFocus