Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Debian: 2010-2150 Important: Rubygem-ActiveoRecord SQL Injection

fedora
Calendar Grey February 27, 2009
Dist Fedora Esm H88
Vital patch for rubygem-rails tackles serious HTTP header vulnerability on CentOS 7.
CVE-2008-5189: CGI header injection vulnerability

Summary

Eases web-request routing, handling, and response as a half-way front,

half-way page controller. Implemented with specific emphasis on enabling easy

unit/integration testing that doesn't require a browser.

CVE-2008-5189: CGI header injection vulnerability

* Thu Feb 26 2009 Jeroen van Meeuwen - 2.1.1-2

- Fix CVE-2008-5189

[ 1 ] Bug #472510 - CVE-2008-5189 rubygems-actionpack: redirect HTTP header injection vulnerability

https://bugzilla.redhat.com/show_bug.cgi?id=472510

su -c 'yum update rubygem-actionpack' at the command line.

For more information, refer to "Managing Software with yum",

available at .

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

Fedora-package-announce mailing list

Fedora-package-announce@redhat.com

https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 10
Version: 2.1.1
Release: 2.fc10
Summary: Web-flow and rendering framework putting the VC in MVC

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here