Alerts This Week
Warning Icon 1 609
Alerts This Week
Warning Icon 1 609

Fedora 25: FEDORA-2017-ca05b30e86 Moderate: rubygem-yard Directory Attack

fedora
Calendar Grey December 12, 2017
Dist Fedora Esm H88
Fedora 25 rubygem-yarn upgrade tackles directory exposure vulnerabilities, delivering essential solutions for its user base.
Fix to directory traversal attacks (CVE-2017-17042).

Summary

YARD is a documentation generation tool for the Ruby programming language.

It enables the user to generate consistent, usable documentation that can be

exported to a number of formats very easily, and also supports extending for

custom Ruby constructs such as custom class level definitions.

Fix to directory traversal attacks (CVE-2017-17042).

[ 1 ] Bug #1519065 - CVE-2017-17042 rubygem-yard: (lib/yard/core_ext/file.rb) is vulnerable to directory traversal attacks

https://bugzilla.redhat.com/show_bug.cgi?id=1519065

su -c 'dnf upgrade rubygem-yard' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Severity
important
Lowest
Low
Medium
High
Critical

Product: Fedora 25
Version: 0.8.7.6
Release: 4.fc25
Summary: Documentation tool for consistent and usable documentation in Ruby

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here