Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Fedora 10: 2009-12966 Moderate: Rubygem-Actionpack CSRF and XSS Fix

fedora
Calendar Grey December 10, 2009
Dist Fedora Esm H88
Two significant vulnerabilities in rubygem-actionpack on Fedora 10 addressed to bolster defenses against CSRF and XSS threats.
Two security issues are found on activepack shipped on Fedora 10

Summary

Eases web-request routing, handling, and response as a half-way front,

half-way page controller. Implemented with specific emphasis on enabling easy

unit/integration testing that doesn't require a browser.

Update Information:

Two security issues are found on activepack shipped on Fedora 10. One bug is that there is a weakness in the strip_tags function in ruby on rails (bug 542786, CVE-2009-4214). Another one is a possibility to circumvent protection against cross-site request forgery (CSRF) attacks (bug 544329). This new rpm will fix these issues.

Change Log

* Mon Dec 7 2009 Mamoru Tasaka - 2.1.1-5 - Fix for potential CSRF protection circumvention (bug 544329) - Fix for XSS weakness in strip_tags (bug 542786) * Mon Sep 21 2009 Mamoru Tasaka - 2.1.1-3 - Patch for CVE-2009-3009 (bug 520843) * Thu Feb 26 2009 Jeroen van Meeuwen - 2.1.1-2 - Fix CVE-2008-5189

References


[ 1 ] Bug #542786 - rubygem-actionpack: XSS weakness in strip_tags https://bugzilla.redhat.com/show_bug.cgi?id=542786 [ 2 ] Bug #544329 - rubygem-actionpack: Potential CSRF protection circumvention https://bugzilla.redhat.com/show_bug.cgi?id=544329

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-actionpack' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: rubygem-actionpack
Product: Fedora 10
Version: 2.1.1
Release: 5.fc10
Summary: Web-flow and rendering framework putting the VC in MVC

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here