[ELSA-2013-0612] ruby security update

Severity Moderate
Affected Packages 9
CVEs 2

[1.8.7.352-10]
- escaping vulnerability about Exception#to_s / NameError#to_s
* ruby-1.8.7-p371-CVE-2012-4481.patch
- Related: rhbz#915379

[1.8.7.352-9]
- Fix regression introduced by fix for entity expansion DOS vulnerability
in REXML (https://bugs.ruby-lang.org/issues/7961)
* ruby-2.0.0-add-missing-rexml-require.patch
- Related: rhbz#915379

[1.8.7.352-8]
- Addresses entity expansion DoS vulnerability in REXML.
* ruby-2.0.0-entity-expansion-DoS-vulnerability-in-REXML.patch
- Resolves: rhbz#915379

ID
ELSA-2013-0612
Severity
moderate
URL
https://linux.oracle.com/errata/ELSA-2013-0612.html
Published
2013-03-07T00:00:00
(11 years ago)
Modified
2013-03-07T00:00:00
(11 years ago)
Rights
Copyright 2013 Oracle, Inc.
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/oraclelinux/ruby?distro=oraclelinux-6.4 oraclelinux ruby < 1.8.7.352-10.el6_4 oraclelinux-6.4
Affected pkg:rpm/oraclelinux/ruby-tcltk?distro=oraclelinux-6.4 oraclelinux ruby-tcltk < 1.8.7.352-10.el6_4 oraclelinux-6.4
Affected pkg:rpm/oraclelinux/ruby-static?distro=oraclelinux-6.4 oraclelinux ruby-static < 1.8.7.352-10.el6_4 oraclelinux-6.4
Affected pkg:rpm/oraclelinux/ruby-ri?distro=oraclelinux-6.4 oraclelinux ruby-ri < 1.8.7.352-10.el6_4 oraclelinux-6.4
Affected pkg:rpm/oraclelinux/ruby-rdoc?distro=oraclelinux-6.4 oraclelinux ruby-rdoc < 1.8.7.352-10.el6_4 oraclelinux-6.4
Affected pkg:rpm/oraclelinux/ruby-libs?distro=oraclelinux-6.4 oraclelinux ruby-libs < 1.8.7.352-10.el6_4 oraclelinux-6.4
Affected pkg:rpm/oraclelinux/ruby-irb?distro=oraclelinux-6.4 oraclelinux ruby-irb < 1.8.7.352-10.el6_4 oraclelinux-6.4
Affected pkg:rpm/oraclelinux/ruby-docs?distro=oraclelinux-6.4 oraclelinux ruby-docs < 1.8.7.352-10.el6_4 oraclelinux-6.4
Affected pkg:rpm/oraclelinux/ruby-devel?distro=oraclelinux-6.4 oraclelinux ruby-devel < 1.8.7.352-10.el6_4 oraclelinux-6.4
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...