Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

Fedora 39: FEDORA-2023-4f0bb4ff5e Moderate: ActiveRecord File Permissions

fedora
Calendar Grey September 15, 2023
Dist Fedora Esm H88
Fedora 39 release tackles vulnerabilities in ActiveRecord concerning file access rights and includes specifics about the Rails version enhancement.
Ruby on Rails security upgrade: - Versions-7-0-7-2-6-1-7-6-have-been-released - incorrect file permissions on encrypted files

Summary

Implements the ActiveRecord pattern (Fowler, PoEAA) for ORM. It ties database

tables and classes together for business objects, like Customer or

Subscription, that can find, save, and destroy themselves without resorting to

manual SQL.

Update Information:

Ruby on Rails security upgrade: - Versions-7-0-7-2-6-1-7-6-have-been-released - incorrect file permissions on encrypted files. Exploit not known.

Change Log

* Mon Aug 28 2023 Pavel Valena - 1:7.0.7.2-1 - Update to activerecord 7.0.7.2.

References

Fedora Update Notification FEDORA-2023-4f0bb4ff5e 2023-09-15 18:36:13.240099 Name : rubygem-activerecord Product : Fedora 39 Version : 7.0.7.2 Release : 1.fc39 URL : https://rubyonrails.org/ Summary : Object-relational mapper framework (part of Rails) Description : Implements the ActiveRecord pattern (Fowler, PoEAA) for ORM. It ties database tables and classes together for business objects, like Customer or Subscription, that can find, save, and destroy themselves without resorting to manual SQL.

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-4f0bb4ff5e' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Name: rubygem-activerecord
Product: Fedora 39
Version: 7.0.7.2
Release: 1.fc39
Summary: Object-relational mapper framework (part of Rails)

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here