drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Unsichere Verwendung temporärer Verzeichnisse in rubygem-passenger
Name: |
Unsichere Verwendung temporärer Verzeichnisse in rubygem-passenger |
|
ID: |
FEDORA-2013-13234 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 18 |
|
Datum: |
Mi, 31. Juli 2013, 08:14 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4136 |
|
Applikationen: |
rubygem-passenger |
|
Originalnachricht |
Name : rubygem-passenger Product : Fedora 18 Version : 3.0.21 Release : 4.fc18 URL : http://www.modrails.com Summary : Passenger Ruby web application server Description : Phusion Passenger™ — a.k.a. mod_rails or mod_rack — makes deployment of Ruby web applications, such as those built on the revolutionary Ruby on Rails web framework, a breeze. It follows the usual Ruby on Rails conventions, such as “Don’t-Repeat-Yourself”.
------------------------------------------------------------------------------- - Update Information:
Fix for CVE-2013-4136 (#985634) ------------------------------------------------------------------------------- - ChangeLog:
* Thu Jul 18 2013 Troy Dawson <tdawson@redhat.com> - 3.0.21-4 - Fix for CVE-2013-4136 (#985634) * Fri Jun 21 2013 Troy Dawson <tdawson@redhat.com> - 3.0.21-3 - Putting the agents back to where they originally were * Fri Jun 21 2013 Troy Dawson <tdawson@redhat.com> - 3.0.21-2 - Remove Rakefile (only used for building) (#976843) * Thu May 30 2013 Troy Dawson <tdawson@redhat.com> - 3.0.21-1 - Update to version 3.0.21 - Fix for CVE-2013-2119 * Thu May 16 2013 Troy Dawson <tdawson@redhat.com> - 3.0.19-4 - Fix to make agents work on F19+ * Wed Mar 13 2013 Troy Dawson <tdawson@redhat.com> - 3.0.19-3 - Fix to make it build/install on F19+ - Added patch105 * Thu Feb 14 2013 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 3.0.19-2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_19_Mass_Rebuild * Sun Jan 20 2013 Orion Poplawski <orion@cora.nwra.com> - 3.0.19-1 - Update to 3.0.19 * Wed Sep 19 2012 Orion Poplawski <orion@cora.nwra.com> - 3.0.17-3 - Drop dependency on rubygem(file-tail), no longer needed ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #985633 - CVE-2013-4136 rubygem-passenger: insecure temporary directory usage due to reuse of existing server instance directories https://bugzilla.redhat.com/show_bug.cgi?id=985633 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-passenger' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|