[ELSA-2013-0129] ruby security and bug fix update
Severity
Moderate
Affected Packages
9
CVEs
2
[1.8.5-27]
- unintentional file creation caused by inserting an illegal NUL character
* ruby-1.8.6-CVE-2012-4522-io.c-pipe_open-command-name-should-not-contain-null-.patch
- Related: rhbz#867750
[1.8.5-26]
- escaping vulnerability about Exception#to_s / NameError#to_s
* ruby-1.8.7-p371-CVE-2012-4481.patch
- Resolves: rhbz#867750
- unintentional file creation caused by inserting an illegal NUL character
* ruby-1.8.6-CVE-2012-4522-io.c-rb_open_file-should-check-NUL-in-path.patch
- Resolves: rhbz#867750
[1.8.5-25]
- Resolve buffer overflow causing gem installation issues.
* ruby-1.8.7-syck-avoid-buffer-overflow.patch
- Resolves: rhbz#834381
Package | Affected Version |
---|---|
pkg:rpm/oraclelinux/ruby?distro=oraclelinux-5 | < 1.8.5-27.el5 |
pkg:rpm/oraclelinux/ruby-tcltk?distro=oraclelinux-5 | < 1.8.5-27.el5 |
pkg:rpm/oraclelinux/ruby-ri?distro=oraclelinux-5 | < 1.8.5-27.el5 |
pkg:rpm/oraclelinux/ruby-rdoc?distro=oraclelinux-5 | < 1.8.5-27.el5 |
pkg:rpm/oraclelinux/ruby-mode?distro=oraclelinux-5 | < 1.8.5-27.el5 |
pkg:rpm/oraclelinux/ruby-libs?distro=oraclelinux-5 | < 1.8.5-27.el5 |
pkg:rpm/oraclelinux/ruby-irb?distro=oraclelinux-5 | < 1.8.5-27.el5 |
pkg:rpm/oraclelinux/ruby-docs?distro=oraclelinux-5 | < 1.8.5-27.el5 |
pkg:rpm/oraclelinux/ruby-devel?distro=oraclelinux-5 | < 1.8.5-27.el5 |
- ID
- ELSA-2013-0129
- Severity
- moderate
- URL
- https://linux.oracle.com/errata/ELSA-2013-0129.html
- Published
-
2013-01-11T00:00:00
(11 years ago) - Modified
-
2013-01-11T00:00:00
(11 years ago) - Rights
- Copyright 2013 Oracle, Inc.
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
elsa | ELSA-2013-0129 | http://linux.oracle.com/errata/ELSA-2013-0129.html | |
CVE | CVE-2012-4481 | http://linux.oracle.com/cve/CVE-2012-4481 | |
CVE | CVE-2012-4522 | http://linux.oracle.com/cve/CVE-2012-4522 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/oraclelinux/ruby?distro=oraclelinux-5 | oraclelinux | ruby | < 1.8.5-27.el5 | oraclelinux-5 | ||
Affected | pkg:rpm/oraclelinux/ruby-tcltk?distro=oraclelinux-5 | oraclelinux | ruby-tcltk | < 1.8.5-27.el5 | oraclelinux-5 | ||
Affected | pkg:rpm/oraclelinux/ruby-ri?distro=oraclelinux-5 | oraclelinux | ruby-ri | < 1.8.5-27.el5 | oraclelinux-5 | ||
Affected | pkg:rpm/oraclelinux/ruby-rdoc?distro=oraclelinux-5 | oraclelinux | ruby-rdoc | < 1.8.5-27.el5 | oraclelinux-5 | ||
Affected | pkg:rpm/oraclelinux/ruby-mode?distro=oraclelinux-5 | oraclelinux | ruby-mode | < 1.8.5-27.el5 | oraclelinux-5 | ||
Affected | pkg:rpm/oraclelinux/ruby-libs?distro=oraclelinux-5 | oraclelinux | ruby-libs | < 1.8.5-27.el5 | oraclelinux-5 | ||
Affected | pkg:rpm/oraclelinux/ruby-irb?distro=oraclelinux-5 | oraclelinux | ruby-irb | < 1.8.5-27.el5 | oraclelinux-5 | ||
Affected | pkg:rpm/oraclelinux/ruby-docs?distro=oraclelinux-5 | oraclelinux | ruby-docs | < 1.8.5-27.el5 | oraclelinux-5 | ||
Affected | pkg:rpm/oraclelinux/ruby-devel?distro=oraclelinux-5 | oraclelinux | ruby-devel | < 1.8.5-27.el5 | oraclelinux-5 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |