Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Red Hat OpenShift Enterprise 1.1.1 RHSA-2013:0582-01: Moderate Remote Risk

red hat
Calendar Grey February 28, 2013
Dist Redhat Esm H88
Ubuntu announces significant patch for Kubernetes 2.5.4, tackling essential vulnerabilities. Update immediately!
Red Hat OpenShift Enterprise 1.1.1 is now available

Solution

Before applying this update, make sure all previously-released errata relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/knowledge/articles/11258

Summary

OpenShift Enterprise is a cloud computing Platform-as-a-Service (PaaS) solution from Red Hat, and is designed for on-premise or private cloud deployments.
Installing the updated packages and restarting the OpenShift services are the only requirements for this update. However, if you are updating your system to Red Hat Enterprise Linux 6.4 while applying OpenShift Enterprise 1.1.1 updates, it is recommended that you restart your system.
For further information about this release, refer to the OpenShift Enterprise 1.1.1 Technical Notes, available shortly from https://access.redhat.com/knowledge/docs/
This update also fixes the following security issues:
Multiple cross-site scripting (XSS) flaws were found in rubygem-actionpack. A remote attacker could use these flaws to conduct XSS attacks against users of an application using rubygem-actionpack. (CVE-2012-3463, CVE-2012-3464, CVE-2012-3465)
It was found that certain methods did not sanitize file names before passing them to lower layer routines in Ruby. If a Ruby application created files with names based on untrusted input, it could result in the creation of files with different names than expected. (CVE-2012-4522)
A denial of service flaw was found in the implementation of associative arrays (hashes) in Ruby. An attacker able to supply a large number of inputs to a Ruby application (such as HTTP POST request parameters sent to a web application) that are used as keys when inserting data into an array could trigger multiple hash function collisions, making array operations take an excessive amount of CPU time. To mitigate this issue, a new, more collision resistant algorithm has been used to reduce the chance of an attacker successfully causing intentional collisions. (CVE-2012-5371)
Input validation vulnerabilities were discovered in rubygem-activerecord. A remote attacker could possibly use these flaws to perform an SQL injection attack against an application using rubygem-activerecord. (CVE-2012-2661, CVE-2012-2695, CVE-2013-0155)
Input validation vulnerabilities were discovered in rubygem-actionpack. A remote attacker could possibly use these flaws to perform an SQL injection attack against an application using rubygem-actionpack and rubygem-activerecord. (CVE-2012-2660, CVE-2012-2694)
A flaw was found in the HTTP digest authentication implementation in rubygem-actionpack. A remote attacker could use this flaw to cause a denial of service of an application using rubygem-actionpack and digest authentication. (CVE-2012-3424)
A flaw was found in the handling of strings in Ruby safe level 4. A remote attacker can use Exception#to_s to destructively modify an untainted string so that it is tainted, the string can then be arbitrarily modified. (CVE-2012-4466)
A flaw was found in the method for translating an exception message into a string in the Ruby Exception class. A remote attacker could use this flaw to bypass safe level 4 restrictions, allowing untrusted (tainted) code to modify arbitrary, trusted (untainted) strings, which safe level 4 restrictions would otherwise prevent. (CVE-2012-4464)
It was found that ruby_parser from rubygem-ruby_parser created a temporary file in an insecure way. A local attacker could use this flaw to perform a symbolic link attack, overwriting arbitrary files accessible to the application using ruby_parser. (CVE-2013-0162)
The CVE-2013-0162 issue was discovered by Michael Scherer of the Red Hat Regional IT team.
Users are advised to upgrade to Red Hat OpenShift Enterprise 1.1.1.

References

https://access.redhat.com/security/cve/CVE-2012-2660 https://access.redhat.com/security/cve/CVE-2012-2661 https://access.redhat.com/security/cve/CVE-2012-2694 https://access.redhat.com/security/cve/CVE-2012-2695 https://access.redhat.com/security/cve/CVE-2012-3424 https://access.redhat.com/security/cve/CVE-2012-3463 https://access.redhat.com/security/cve/CVE-2012-3464 https://access.redhat.com/security/cve/CVE-2012-3465 https://access.redhat.com/security/cve/CVE-2012-4464 https://access.redhat.com/security/cve/CVE-2012-4466 https://access.redhat.com/security/cve/CVE-2012-4522 https://access.redhat.com/security/cve/CVE-2012-5371 https://access.redhat.com/security/cve/CVE-2013-0155 https://access.redhat.com/security/cve/CVE-2013-0162 https://access.redhat.com/security/updates/classification/#moderate https://access.redhat.com/knowledge/docs/

Package List

Red Hat OpenShift Enterprise Infrastructure:
Source:
noarch: openshift-console-0.0.16-1.el6op.noarch.rpm openshift-origin-broker-1.0.11-1.el6op.noarch.rpm openshift-origin-broker-util-1.0.15-1.el6op.noarch.rpm ruby193-ruby-irb-1.9.3.327-25.el6.noarch.rpm ruby193-rubygem-actionpack-3.2.8-3.el6.noarch.rpm ruby193-rubygem-actionpack-doc-3.2.8-3.el6.noarch.rpm ruby193-rubygem-activemodel-3.2.8-2.el6.noarch.rpm ruby193-rubygem-activemodel-doc-3.2.8-2.el6.noarch.rpm ruby193-rubygem-activerecord-3.2.8-3.el6.noarch.rpm ruby193-rubygem-activerecord-doc-3.2.8-3.el6.noarch.rpm ruby193-rubygem-minitest-2.5.1-25.el6.noarch.rpm ruby193-rubygem-railties-3.2.8-2.el6.noarch.rpm ruby193-rubygem-railties-doc-3.2.8-2.el6.noarch.rpm ruby193-rubygem-rake-0.9.2.2-25.el6.noarch.rpm ruby193-rubygem-ruby_parser-2.3.1-3.el6op.noarch.rpm ruby193-rubygem-ruby_parser-doc-2.3.1-3.el6op.noarch.rpm ruby193-rubygems-1.8.23-25.el6.noarch.rpm ruby193-rubygems-devel-1.8.23-25.el6.noarch.rpm rubygem-actionpack-3.0.13-4.el6op.noarch.rpm rubygem-activemodel-3.0.13-3.el6op.noarch.rpm rubygem-activemodel-doc-3.0.13-3.el6op.noarch.rpm rubygem-activerecord-3.0.13-5.el6op.noarch.rpm rubygem-bson-1.8.1-2.el6op.noarch.rpm rubygem-mongo-1.8.1-2.el6op.noarch.rpm rubygem-mongo-doc-1.8.1-2.el6op.noarch.rpm

Read the Full Advisory


Advisory ID: RHSA-2013:0582-01
Product: Red Hat OpenShift Enterprise
Issue date: 2013-02-28

Topic

Red Hat OpenShift Enterprise 1.1.1 is now available.The Red Hat Security Response Team has rated this update as having moderatesecurity impact. Common Vulnerability Scoring System (CVSS) base scores,which give detailed severity ratings, are available for each vulnerabilityfrom the CVE links in the References section.

Relevant Releases Architectures

Red Hat OpenShift Enterprise Infrastructure - noarch, x86_64

Red Hat OpenShift Enterprise JBoss EAP add-on - noarch

Red Hat OpenShift Enterprise Node - noarch, x86_64

Bugs Fixed

827353 - CVE-2012-2660 rubygem-actionpack: Unsafe query generation

827363 - CVE-2012-2661 rubygem-activerecord: SQL injection when processing nested query paramaters831573 - CVE-2012-2695 rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661)

831581 - CVE-2012-2694 rubygem-actionpack: Unsafe query generation (a different flaw than CVE-2012-2660)

843711 - CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest

847196 - CVE-2012-3463 rubygem-actionpack: potential XSS vulnerability in select_tag prompt

847199 - CVE-2012-3464 rubygem-actionpack: potential XSS vulnerability

847200 - CVE-2012-3465 rubygem-actionpack: XSS Vulnerability in strip_tags

862598 - CVE-2012-4464 ruby 1.9.3: Possibility to bypass Ruby's $SAFE (level 4) semantics

862614 - CVE-2012-4466 ruby: safe level bypass via name_err_mesg_to_str()

865940 - CVE-2012-4522 ruby: unintentional file creation caused by inserting an illegal NUL character

875236 - CVE-2012-5371 ruby: Murmur hash-flooding DoS flaw in ruby 1.9 (oCERT-2012-001)

887353 - [Cartridge] Removing a cartridge leaves its info directory in place

889426 - The "scale your application" page for scalable app displayed not well

892806 - CVE-2013-0162 rubygem-ruby_parser: incorrect temporary file usage

Read the Full Advisory

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here