drucken bookmarks versenden konfigurieren admin pdf Sicherheit: Zwei Probleme in rubygem-activerecord
Name: |
Zwei Probleme in rubygem-activerecord |
|
ID: |
FEDORA-2014-3169 |
|
Distribution: |
Fedora |
|
Plattformen: |
Fedora 20 |
|
Datum: |
Di, 11. März 2014, 07:05 |
|
Referenzen: |
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0080
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0081 |
|
Applikationen: |
Active Record |
|
Originalnachricht |
Name : rubygem-activerecord Product : Fedora 20 Version : 4.0.0 Release : 2.fc20 URL : http://www.rubyonrails.org Summary : Implements the ActiveRecord pattern for ORM Description : Implements the ActiveRecord pattern (Fowler, PoEAA) for ORM. It ties database tables and classes together for business objects, like Customer or Subscription, that can find, save, and destroy themselves without resorting to manual SQL.
------------------------------------------------------------------------------- - Update Information:
This fixes Ruby on Rails 4.0.3 security CVEs:
- CVE-2014-0080
- CVE-2014-0081
------------------------------------------------------------------------------- - ChangeLog:
* Wed Feb 26 2014 Josef Stribny <jstribny@redhat.com> - 1:4.0.0-2 - Fix CVE-2014-0080: PostgreSQL array data injection vulnerability - Fix SQLite tests ------------------------------------------------------------------------------- - References:
[ 1 ] Bug #1065520 - CVE-2014-0081 rubygem-actionpack: number_to_currency, number_to_percentage and number_to_human XSS vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1065520 [ 2 ] Bug #1065517 - CVE-2014-0080 rubygem-activerecord: PostgreSQL array data injection vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=1065517 ------------------------------------------------------------------------------- -
This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-activerecord' at the command line. For more information, refer to "Managing Software with yum", available at http://docs.fedoraproject.org/yum/.
All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/keys ------------------------------------------------------------------------------- - _______________________________________________ package-announce mailing list package-announce@lists.fedoraproject.org https://admin.fedoraproject.org/mailman/listinfo/package-announce
|
|
|
|