ELSA-2011-0908

ELSA-2011-0908 - ruby security update

Type:SECURITY
Severity:MODERATE
Release Date:2011-06-28

Description



[1.8.1-16.el4]
- Comply with guidelines
- Related: rhbz#709959

[1.8.1-15.el4]
- Address CVE-2011-1005 'Untrusted codes able to modify arbitrary strings'
* ruby-1.8.7-CVE-2011-1005.patch
- Address CVE-2011-0188 'memory corruption in BigDecimal on 64bit platforms'
* ruby-1.8.7-CVE-2011-0188.patch
- Address CVE-CVE-2010-0541 'Ruby WEBrick javascript injection flaw'
* ruby-1.8.7-CVE-2010-0541.patch
- Address CVE-CVE-2009-4492 'ruby WEBrick log escape sequence'
* ruby-1.8.6-CVE-2009-4492.patch
- Resolves: rhbz#709959


Related CVEs


CVE-2009-4492
CVE-2010-0541
CVE-2011-0188
CVE-2011-1005

Updated Packages


Release/ArchitectureFilenameMD5sumSuperseded By Advisory
Oracle Linux 4 (i386) ruby-1.8.1-16.el4.src.rpm5c37c2dbc361e8a931a919c6b59ff7a4ELSA-2012-0070
irb-1.8.1-16.el4.i386.rpm6d143e3e5fe38965193dfa0262d8e3afELSA-2012-0070
ruby-1.8.1-16.el4.i386.rpm071d2a334e6d1613b26bcdef7fe9a40cELSA-2012-0070
ruby-devel-1.8.1-16.el4.i386.rpm7f5fa44c1b294cf096b46d5187ae27d4ELSA-2012-0070
ruby-docs-1.8.1-16.el4.i386.rpmff3bcdada57b93a3b4cf8c45bfcbfbd6ELSA-2012-0070
ruby-libs-1.8.1-16.el4.i386.rpm67765d846750a553e778a1b979d50887ELSA-2012-0070
ruby-mode-1.8.1-16.el4.i386.rpm23366aef56bbd1288b9fcd7f675dcfceELSA-2012-0070
ruby-tcltk-1.8.1-16.el4.i386.rpm6fb1e2e8a905f0fd6d1737a8fbcadebaELSA-2012-0070
Oracle Linux 4 (ia64) ruby-1.8.1-16.el4.src.rpm5c37c2dbc361e8a931a919c6b59ff7a4ELSA-2012-0070
irb-1.8.1-16.el4.ia64.rpm16ddc17f9cd931d3e4b7bf009828493cELSA-2012-0070
ruby-1.8.1-16.el4.ia64.rpm5c2361bdc2e9e6e685af2b7f421c7e62ELSA-2012-0070
ruby-devel-1.8.1-16.el4.ia64.rpmba9490cefd8626205557377fb10b1a40ELSA-2012-0070
ruby-docs-1.8.1-16.el4.ia64.rpm2916fc8220147b9b62b4135bb4a0458aELSA-2012-0070
ruby-libs-1.8.1-16.el4.i386.rpm67765d846750a553e778a1b979d50887ELSA-2012-0070
ruby-libs-1.8.1-16.el4.ia64.rpm3889ada2eb8cf23e5fb603797a6de290ELSA-2012-0070
ruby-mode-1.8.1-16.el4.ia64.rpm207f07721322134268d6745a45e834a9ELSA-2012-0070
ruby-tcltk-1.8.1-16.el4.ia64.rpmf9d8618c098e3e0327e5d7fa4880f94dELSA-2012-0070
Oracle Linux 4 (x86_64) ruby-1.8.1-16.el4.src.rpm5c37c2dbc361e8a931a919c6b59ff7a4ELSA-2012-0070
irb-1.8.1-16.el4.x86_64.rpm00c33c54c27d737e59dee632e54c7d20ELSA-2012-0070
ruby-1.8.1-16.el4.x86_64.rpm34e863002841b9740e7007b9d0da73fcELSA-2012-0070
ruby-devel-1.8.1-16.el4.x86_64.rpm4756bf25d3a78200f8f52dbf2696b80eELSA-2012-0070
ruby-docs-1.8.1-16.el4.x86_64.rpm811780243b3c771d627a24e1582e012cELSA-2012-0070
ruby-libs-1.8.1-16.el4.i386.rpm67765d846750a553e778a1b979d50887ELSA-2012-0070
ruby-libs-1.8.1-16.el4.x86_64.rpm2bd4db53acc8e37466f0ef1740629938ELSA-2012-0070
ruby-mode-1.8.1-16.el4.x86_64.rpm8ff736f67db7a286f9dbda8a0137d2f5ELSA-2012-0070
ruby-tcltk-1.8.1-16.el4.x86_64.rpmfb3bf60f8ba50c42b632984192d9e528ELSA-2012-0070



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete