drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Denial of Service in rubygems
Name: |
Denial of Service in rubygems |
|
ID: |
FEDORA-2013-16316 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 18 |
|
Datum: |
Sa, 21. September 2013, 10:45 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4287 |
|
Applikationen: |
Ruby |
|
Originalnachricht |
Name : rubygems Product : Fedora 18 Version : 1.8.25 Release : 7.fc18 URL : https://rubygems.org/ Summary : The Ruby standard for packaging ruby libraries Description : RubyGems is the Ruby standard for publishing and managing third party libraries.
------------------------------------------------------------------------------- - Update Information:
A vulnerability was found on rubygems currently being shipped on Fedora in validating versions with a regular expression which leads to denial of service due to backtracking. This issue are now assigned as CVE-2013-4287.
This new rpm will fix this issue.
------------------------------------------------------------------------------- - ChangeLog:
* Tue Sep 10 2013 Mamoru TASAKA <mtasaka@fedoraproject.org> - 1.8.25-7 - Backport from 1.8.26 to fix CVE-2013-4287 * Tue Mar 26 2013 Mamoru TASAKA <mtasaka@fedoraproject.org> - 1.8.25-6 - Fix %gem_extdir_mri directory on F-18 and below * Fri Mar 8 2013 Mamoru TASAKA <mtasaka@fedoraproject.org> - 1.8.25-5 - Detect json / io-console directory at %check - Prevent squash of %gem_install with following line (Vít Ondruch <vondruch@redhat.com>) * Mon Feb 25 2013 Mamoru TASAKA <mtasaka@fedoraproject.org> - 1.8.25-4 - Backport %gem_extdir_mri also * Mon Feb 25 2013 Mamoru TASAKA <mtasaka@fedoraproject.org> - 1.8.25-3 - And slightly change %gem_install because rubygems 1.8.25 does not support --document=ri,rdoc style (Vít Ondruch <vondruch@redhat.com>) * Mon Feb 25 2013 Mamoru TASAKA <mtasaka@fedoraproject.org> - 1.8.25-2 - Backport %gem_install macro * Tue Feb 5 2013 Mamoru TASAKA <mtasaka@fedoraproject.org> - 1.8.25-1 - 1.8.25 * Tue Feb 5 2013 Mamoru TASAKA <mtasaka@fedoraproject.org> - 1.8.24-4 - Bump release ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update rubygems' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|