[ELSA-2013-0612] ruby security update
Severity
Moderate
Affected Packages
9
CVEs
2
[1.8.7.352-10]
- escaping vulnerability about Exception#to_s / NameError#to_s
* ruby-1.8.7-p371-CVE-2012-4481.patch
- Related: rhbz#915379
[1.8.7.352-9]
- Fix regression introduced by fix for entity expansion DOS vulnerability
in REXML (https://bugs.ruby-lang.org/issues/7961)
* ruby-2.0.0-add-missing-rexml-require.patch
- Related: rhbz#915379
[1.8.7.352-8]
- Addresses entity expansion DoS vulnerability in REXML.
* ruby-2.0.0-entity-expansion-DoS-vulnerability-in-REXML.patch
- Resolves: rhbz#915379
Package | Affected Version |
---|---|
pkg:rpm/oraclelinux/ruby?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
pkg:rpm/oraclelinux/ruby-tcltk?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
pkg:rpm/oraclelinux/ruby-static?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
pkg:rpm/oraclelinux/ruby-ri?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
pkg:rpm/oraclelinux/ruby-rdoc?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
pkg:rpm/oraclelinux/ruby-libs?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
pkg:rpm/oraclelinux/ruby-irb?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
pkg:rpm/oraclelinux/ruby-docs?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
pkg:rpm/oraclelinux/ruby-devel?distro=oraclelinux-6.4 | < 1.8.7.352-10.el6_4 |
- ID
- ELSA-2013-0612
- Severity
- moderate
- URL
- https://linux.oracle.com/errata/ELSA-2013-0612.html
- Published
-
2013-03-07T00:00:00
(11 years ago) - Modified
-
2013-03-07T00:00:00
(11 years ago) - Rights
- Copyright 2013 Oracle, Inc.
- Other Advisories
Source | # ID | Name | URL |
---|---|---|---|
elsa | ELSA-2013-0612 | http://linux.oracle.com/errata/ELSA-2013-0612.html | |
CVE | CVE-2012-4481 | http://linux.oracle.com/cve/CVE-2012-4481 | |
CVE | CVE-2013-1821 | http://linux.oracle.com/cve/CVE-2013-1821 |
Type | Package URL | Namespace | Name / Product | Version | Distribution / Platform | Arch | Patch / Fix |
---|---|---|---|---|---|---|---|
Affected | pkg:rpm/oraclelinux/ruby?distro=oraclelinux-6.4 | oraclelinux | ruby | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 | ||
Affected | pkg:rpm/oraclelinux/ruby-tcltk?distro=oraclelinux-6.4 | oraclelinux | ruby-tcltk | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 | ||
Affected | pkg:rpm/oraclelinux/ruby-static?distro=oraclelinux-6.4 | oraclelinux | ruby-static | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 | ||
Affected | pkg:rpm/oraclelinux/ruby-ri?distro=oraclelinux-6.4 | oraclelinux | ruby-ri | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 | ||
Affected | pkg:rpm/oraclelinux/ruby-rdoc?distro=oraclelinux-6.4 | oraclelinux | ruby-rdoc | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 | ||
Affected | pkg:rpm/oraclelinux/ruby-libs?distro=oraclelinux-6.4 | oraclelinux | ruby-libs | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 | ||
Affected | pkg:rpm/oraclelinux/ruby-irb?distro=oraclelinux-6.4 | oraclelinux | ruby-irb | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 | ||
Affected | pkg:rpm/oraclelinux/ruby-docs?distro=oraclelinux-6.4 | oraclelinux | ruby-docs | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 | ||
Affected | pkg:rpm/oraclelinux/ruby-devel?distro=oraclelinux-6.4 | oraclelinux | ruby-devel | < 1.8.7.352-10.el6_4 | oraclelinux-6.4 |
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |