Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

Fedora 23: 2016-20459 Moderate: Rubygem-Activejob DoS Resolution

fedora
Calendar Grey June 30, 2015
Scroller Fedora
Essential security patch for rubygem-activesupport in Fedora 22, targeting DoS vulnerabilities and HTML entity concerns in JSON processing.
Fixes for: CVE-2015-3226 Escape HTML entities in JSON keys CVE-2015-3227 XML documents that are too deep can cause an stack overflow, which in turn will cause a potential DoS attac...

Summary

Utility library which carries commonly used classes and

goodies from the Rails framework

Update Information:

Fixes for:

CVE-2015-3226 Escape HTML entities in JSON keys

CVE-2015-3227 XML documents that are too deep can cause an stack overflow, which in turn will cause a potential DoS attack.

Change Log

* Mon Jun 22 2015 Josef Stribny - 1:4.2.0-2 - Fix for CVE-2015-3226 - Related: rhbz#1232310 - Fix for CVE-2015-3227 - Related: rhbz#1232302

References

Fedora Update Notification FEDORA-2015-10538 2015-06-23 03:03:14
Name : rubygem-activesupport Product : Fedora 22 Version : 4.2.0 Release : 2.fc22 URL : https://rubyonrails.org/ Summary : Support and utility classes used by the Rails framework Description : Utility library which carries commonly used classes and goodies from the Rails framework

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-activesupport' at the command line. For more information, refer to "Managing Software with yum", available at .

Name: rubygem-activesupport
Product: Fedora 22
Version: 4.2.0
Release: 2.fc22
Summary: Support and utility classes used by the Rails framework

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.