Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

Fedora: 10 Rubygem-Actionpack Moderate: XSS Injection Resolved

fedora
Calendar Grey September 24, 2009
Dist Fedora Esm H88
Keep your Ruby on Rails on Fedora secure by following our guide to update your system and mitigate the HTML injection vulnerability with ease
A vulnerability is found on Ruby on Rails in the escaping code for the form helpers, which also affects the rpms shipped in Fedora Project

Summary

Eases web-request routing, handling, and response as a half-way front,

half-way page controller. Implemented with specific emphasis on enabling easy

unit/integration testing that doesn't require a browser.

Update Information:

A vulnerability is found on Ruby on Rails in the escaping code for the form helpers, which also affects the rpms shipped in Fedora Project. Attackers who can inject deliberately malformed unicode strings into the form helpers can defeat the escaping checks and inject arbitrary HTML. This issue has been tagged as CVE-2009-3009. These new rpms will fix this issue.

Change Log

* Mon Sep 21 2009 Mamoru Tasaka - 2.1.1-3 - Patch for CVE-2009-3009 (bug 520843) * Thu Feb 26 2009 Jeroen van Meeuwen - 2.1.1-2 - Fix CVE-2008-5189

References


[ 1 ] Bug #520843 - CVE-2009-3009 ruby-activesupport: XSS vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=520843

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-actionpack' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: rubygem-actionpack
Product: Fedora 10
Version: 2.1.1
Release: 3.fc10
Summary: Web-flow and rendering framework putting the VC in MVC

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here