Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 23: Update for Rubygem-Rest-Client Security Issues

fedora
Calendar Grey August 27, 2015
Dist Fedora Esm H88
Patch deployed for rubygem-rest-client in Fedora 23 to resolve session fixation vulnerabilities and improve logging functionalities.
Update to rest-client 1.8.0.

Summary

A simple HTTP and REST client for Ruby, inspired by the Sinatra microframework

style of specifying actions: get, put, post, delete.

Update Information:

Update to rest-client 1.8.0.

Change Log

References


[ 1 ] Bug #1239952 - rubygem-rest-client: FTBFS in rawhide https://bugzilla.redhat.com/show_bug.cgi?id=1239952 [ 2 ] Bug #1205294 - CVE-2015-1820 rubygem-rest-client: session fixation vulnerability Set-Cookie headers present in an HTTP 30x redirection responses [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1205294 [ 3 ] Bug #1118692 - rubygem-rest-client-1.8.0 is available https://bugzilla.redhat.com/show_bug.cgi?id=1118692 [ 4 ] Bug #1240983 - CVE-2015-3448 rubygem-rest-client: unsanitized application logging [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1240983

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-rest-client' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
important
Lowest
Low
Medium
High
Critical

Name: rubygem-rest-client
Product: Fedora 23
Version: 1.8.0
Release: 1.fc23
Summary: Simple HTTP and REST client for Ruby

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here