Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Fedora: 2015-10545 Critical: rubygem-activesupport DoS Mitigation

fedora
Calendar Grey June 30, 2015
Dist Fedora Esm H88
Fedora 21 has launched a key update focused on enhancing security for rubygem-activesupport, addressing critical Denial of Service vulnerabilities that can impact system stability
Fixes for: CVE-2015-3226 Escape HTML entities in JSON keys CVE-2015-3227 XML documents that are too deep can cause an stack overflow, which in turn will cause a potential DoS attac...

Summary

Utility library which carries commonly used classes and

goodies from the Rails framework

Update Information:

Fixes for:

CVE-2015-3226 Escape HTML entities in JSON keys

CVE-2015-3227 XML documents that are too deep can cause an stack overflow, which in turn will cause a potential DoS attack.

Change Log

* Mon Jun 22 2015 Josef Stribny - 1:4.1.5-2 - Fix for CVE-2015-3226 - Related: rhbz#1232310 - Fix for CVE-2015-3227 - Related: rhbz#1232302

References

Fedora Update Notification FEDORA-2015-10545 2015-06-23 03:03:31
Name : rubygem-activesupport Product : Fedora 21 Version : 4.1.5 Release : 2.fc21 URL : https://rubyonrails.org/ Summary : Support and utility classes used by the Rails framework Description : Utility library which carries commonly used classes and goodies from the Rails framework

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-activesupport' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
critical
Lowest
Low
Medium
High
Critical

Name: rubygem-activesupport
Product: Fedora 21
Version: 4.1.5
Release: 2.fc21
Summary: Support and utility classes used by the Rails framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here