SCIENTIFIC-LINUX-ERRATA Archives

July 2009

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Troy Dawson <[log in to unmask]>
Reply To:
Troy Dawson <[log in to unmask]>
Date:
Thu, 2 Jul 2009 16:48:24 -0500
Content-Type:
text/plain
Parts/Attachments:
text/plain (72 lines)
Synopsis:	Moderate: ruby security update
Issue date:	2009-07-02
CVE Names:	CVE-2007-1558 CVE-2009-0642 CVE-2009-1904

A flaw was found in the way the Ruby POP module processed certain APOP
authentication requests. By sending certain responses when the Ruby APOP
module attempted to authenticate using APOP against a POP server, a 
remote attacker could, potentially, acquire certain portions of a user's
authentication credentials. (CVE-2007-1558)

It was discovered that Ruby did not properly check the return value when
verifying X.509 certificates. This could, potentially, allow a remote
attacker to present an invalid X.509 certificate, and have Ruby treat it 
as valid. (CVE-2009-0642)

A flaw was found in the way Ruby converted BigDecimal objects to Float
numbers. If an attacker were able to provide certain input for the
BigDecimal object converter, they could crash an application using this
class. (CVE-2009-1904)

SL 4.x

      SRPMS:
ruby-1.8.1-7.el4_8.3.src.rpm
      i386:
irb-1.8.1-7.el4_8.3.i386.rpm
ruby-1.8.1-7.el4_8.3.i386.rpm
ruby-devel-1.8.1-7.el4_8.3.i386.rpm
ruby-docs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-mode-1.8.1-7.el4_8.3.i386.rpm
ruby-tcltk-1.8.1-7.el4_8.3.i386.rpm
      x86_64:
irb-1.8.1-7.el4_8.3.x86_64.rpm
ruby-1.8.1-7.el4_8.3.x86_64.rpm
ruby-devel-1.8.1-7.el4_8.3.x86_64.rpm
ruby-docs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-libs-1.8.1-7.el4_8.3.i386.rpm
ruby-libs-1.8.1-7.el4_8.3.x86_64.rpm
ruby-mode-1.8.1-7.el4_8.3.x86_64.rpm
ruby-tcltk-1.8.1-7.el4_8.3.x86_64.rpm

SL 5.x

      SRPMS:
ruby-1.8.5-5.el5_3.7.src.rpm
      i386:
ruby-1.8.5-5.el5_3.7.i386.rpm
ruby-devel-1.8.5-5.el5_3.7.i386.rpm
ruby-docs-1.8.5-5.el5_3.7.i386.rpm
ruby-irb-1.8.5-5.el5_3.7.i386.rpm
ruby-libs-1.8.5-5.el5_3.7.i386.rpm
ruby-mode-1.8.5-5.el5_3.7.i386.rpm
ruby-rdoc-1.8.5-5.el5_3.7.i386.rpm
ruby-ri-1.8.5-5.el5_3.7.i386.rpm
ruby-tcltk-1.8.5-5.el5_3.7.i386.rpm
      x86_64:
ruby-1.8.5-5.el5_3.7.x86_64.rpm
ruby-devel-1.8.5-5.el5_3.7.i386.rpm
ruby-devel-1.8.5-5.el5_3.7.x86_64.rpm
ruby-docs-1.8.5-5.el5_3.7.x86_64.rpm
ruby-irb-1.8.5-5.el5_3.7.x86_64.rpm
ruby-libs-1.8.5-5.el5_3.7.i386.rpm
ruby-libs-1.8.5-5.el5_3.7.x86_64.rpm
ruby-mode-1.8.5-5.el5_3.7.x86_64.rpm
ruby-rdoc-1.8.5-5.el5_3.7.x86_64.rpm
ruby-ri-1.8.5-5.el5_3.7.x86_64.rpm
ruby-tcltk-1.8.5-5.el5_3.7.x86_64.rpm

-Connie Sieh
-Troy Dawson

ATOM RSS1 RSS2