[FEDORA-2013-17662] Fedora 19: rubygems

Severity Medium
Affected Packages 1
CVEs 2

Previously a security flow was found on rubygems for validating versions with a regular expression which is vulnerable to denial of service due to backtracking. Although this was thought to be fixed in the previous rubygems, the fix was found imcomplete and the imcompleteness is now assigned as CVE-2013-4363.

A packaging bug was found that a directory was not properly owned.

This new rpm will fix this issue.

Package Affected Version
pkg:rpm/fedora/rubygems?distro=fedora-19 < 2.0.10.106.fc19
Source # ID Name URL
Bugzilla 1008866 Bug #1008866 - /usr/share/gems/doc ownership https://bugzilla.redhat.com/show_bug.cgi?id=1008866
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/fedora/rubygems?distro=fedora-19 fedora rubygems < 2.0.10.106.fc19 fedora-19
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...