drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in RubyGems
Name: |
Zwei Probleme in RubyGems |
|
ID: |
USN-1582-1 |
|
Distribution: |
Ubuntu |
|
Plattformen: |
Ubuntu 12.04 LTS |
|
Datum: |
Mi, 26. September 2012, 10:41 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2125
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2126 |
|
Applikationen: |
Ruby |
|
Originalnachricht |
--===============6568605723836443916== Content-Type: multipart/signed; micalg=pgp-sha512; protocol="application/pgp-signature"; boundary="pAwQNkOnpTn9IO2O" Content-Disposition: inline
--pAwQNkOnpTn9IO2O Content-Type: text/plain; charset=us-ascii Content-Disposition: inline
========================================================================== Ubuntu Security Notice USN-1582-1 September 26, 2012
rubygems vulnerabilities ==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.04 LTS
Summary:
RubyGems could be made to download and install malicious gem files.
Software Description: - rubygems: package management framework for Ruby libraries/applications
Details:
John Firebaugh discovered that the RubyGems remote gem fetcher did not properly verify SSL certificates. A remote attacker could exploit this to perform a man in the middle attack to alter gem files being downloaded for installation. (CVE-2012-2126)
John Firebaugh discovered that the RubyGems remote gem fetcher allowed redirection from HTTPS to HTTP. A remote attacker could exploit this to perform a man in the middle attack to alter gem files being downloaded for installation. (CVE-2012-2125)
Update instructions:
The problem can be corrected by updating your system to the following package versions:
Ubuntu 12.04 LTS: rubygems 1.8.15-1ubuntu0.1
In general, a standard system update will make all the necessary changes.
References: http://www.ubuntu.com/usn/usn-1582-1 CVE-2012-2125, CVE-2012-2126
Package Information: https://launchpad.net/ubuntu/+source/rubygems/1.8.15-1ubuntu0.1
--pAwQNkOnpTn9IO2O Content-Type: application/pgp-signature; name="signature.asc" Content-Description: Digital signature
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.11 (GNU/Linux)
iQIcBAEBCgAGBQJQYmcQAAoJENaSAD2qAscK56MP/3tzrE8RxqVRmk+HJvJYJT5J L0tpO88Ptsh9aHnCxw4gC78Zfhys6H3dtiXJ0SjbNf/E+645LeQ/fcLitzR/9ZxT i3yw4hEWwuESf2ZbHmLtGOFpEBcr45maym38nedlS6Ds/r+oyWpB+v53QYzBUo92 TuXFX8D1dod+hObaxh83dHhZMgQGa36QdndO5s1tFsi6Yi/RjnGA6B/EwpuacOuC yn6odpSr/bdCCU2ST/UQiZ0lJiWpzMHzaH43w28e8iZyy9Wy/UInzRjakjyI01z5 h8vwrsiZjmk/lrtDI3s2bnum0+BjOgtklQFY4x59L797XF4uxRG5ZMB70pibIZv2 VHmBs3FlljhlYEZgV5zBFRNZpdPaF8g0TtfPsWoZRcUUNzcscdFK9hOlTUy/XAWs a/PDWG1wkqCxv71BCEbUS0DruHjuBKkuNC1IMULaBm3eevksz0DW/SE2saPLVA1z q/NVJZ5RsgL4ybA/d7N30UQte2UyU7chxFiVOSbE21xhV4fzcUBc+PwRrFqg7Zbi S0mBUvQY0+N9XaUnkZ5TBcc64xavrqET28K2PuWoQXRHDCIPlE43ql8bJjnVAtVl 0bGyFbGUeIDiSmADrUmKkPJ+EDN+1HQnrD68m1mCPbE4AbvQKXPPA7+98rDCveWU re6uROhplleHFKu2HgXa =oxqA -----END PGP SIGNATURE-----
--pAwQNkOnpTn9IO2O--
--===============6568605723836443916== Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline
-- ubuntu-security-announce mailing list ubuntu-security-announce@lists.ubuntu.com Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
--===============6568605723836443916==--
|
|
|
|