Alerts This Week
Warning Icon 1 541
Alerts This Week
Warning Icon 1 541

Fedora 27: FEDORA-2017-386e856a4f Moderate: Rubygem-Yard Directory Attack

fedora
Calendar Grey December 12, 2017
Dist Fedora Esm H88
Mitigating directory traversal vulnerabilities in the rubygem-yard package for Fedora 27 strengthens the overall system defense against potential threats.
Fix to directory traversal attacks (CVE-2017-17042).

Summary

YARD is a documentation generation tool for the Ruby programming language.

It enables the user to generate consistent, usable documentation that can be

exported to a number of formats very easily, and also supports extending for

custom Ruby constructs such as custom class level definitions.

Fix to directory traversal attacks (CVE-2017-17042).

[ 1 ] Bug #1519065 - CVE-2017-17042 rubygem-yard: (lib/yard/core_ext/file.rb) is vulnerable to directory traversal attacks

https://bugzilla.redhat.com/show_bug.cgi?id=1519065

su -c 'dnf upgrade rubygem-yard' at the command line.

For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Change Log

References

Update Instructions

Product: Fedora 27
Version: 0.9.8
Release: 4.fc27
Summary: Documentation tool for consistent and usable documentation in Ruby

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here