Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 586
Alerts This Week
Warning Icon 1 586

Gentoo: GLSA-200711-17 Normal: Ruby on Rails File Threats

gentoo
Calendar Grey November 14, 2007
Scroller Gentoo
Critical vulnerabilities detected in Ruby on Rails on Gentoo Linux, endangering user accounts and file permissions. Immediate action required!
Several vulnerabilities were found in Ruby on Rails allowing for file disclosure and theft of user credentials.

Summary

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Gentoo Linux Security Advisory                           GLSA 200711-17
                                            https://security.gentoo.org/

Severity: Normal Title: Ruby on Rails: Multiple vulnerabilities Date: November 14, 2007 Bugs: #195315, #182223 ID: 200711-17

Synopsis ======= Several vulnerabilities were found in Ruby on Rails allowing for file disclosure and theft of user credentials.
Background ========= Ruby on Rails is a free web framework used to develop database-driven web applications.
Affected packages ================ ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-ruby/rails < 1.2.5 >= 1.2.5
========== candlerb found that ActiveResource, when processing responses using the Hash.from_xm...

Read the Full Advisory

Resolution

References

Availability

style>.gentoo_availability{display:block;}

Concerns

Synopsis

Background

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Affected Packages

Impact

Workaround