Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

Fedora 23: 2016-20459 Moderate: Rubygem-Activejob DoS Resolution

fedora
Calendar Grey June 30, 2015
Dist Fedora Esm H88
Essential security patch for rubygem-activesupport in Fedora 22, targeting DoS vulnerabilities and HTML entity concerns in JSON processing.
Fixes for: CVE-2015-3226 Escape HTML entities in JSON keys CVE-2015-3227 XML documents that are too deep can cause an stack overflow, which in turn will cause a potential DoS attac...

Summary

Utility library which carries commonly used classes and

goodies from the Rails framework

Update Information:

Fixes for:

CVE-2015-3226 Escape HTML entities in JSON keys

CVE-2015-3227 XML documents that are too deep can cause an stack overflow, which in turn will cause a potential DoS attack.

Change Log

* Mon Jun 22 2015 Josef Stribny - 1:4.2.0-2 - Fix for CVE-2015-3226 - Related: rhbz#1232310 - Fix for CVE-2015-3227 - Related: rhbz#1232302

References

Fedora Update Notification FEDORA-2015-10538 2015-06-23 03:03:14
Name : rubygem-activesupport Product : Fedora 22 Version : 4.2.0 Release : 2.fc22 URL : https://rubyonrails.org/ Summary : Support and utility classes used by the Rails framework Description : Utility library which carries commonly used classes and goodies from the Rails framework

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-activesupport' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: rubygem-activesupport
Product: Fedora 22
Version: 4.2.0
Release: 2.fc22
Summary: Support and utility classes used by the Rails framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here