-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: rh-ror50-rubygem-actionpack security update Advisory ID: RHSA-2019:1147-01 Product: Red Hat Software Collections Advisory URL: https://access.redhat.com/errata/RHSA-2019:1147 Issue date: 2019-05-13 CVE Names: CVE-2019-5418 CVE-2019-5419 ==================================================================== 1. Summary: An update for rh-ror50-rubygem-actionpack is now available for Red Hat Software Collections. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch 3. Description: Ruby on Rails is a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components. Security Fix(es): * rubygem-actionpack: render file directory traversal in Action View (CVE-2019-5418) * rubygem-actionpack: denial of service vulnerability in Action View (CVE-2019-5419) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1689159 - CVE-2019-5418 rubygem-actionpack: render file directory traversal in Action View 1689160 - CVE-2019-5419 rubygem-actionpack: denial of service vulnerability in Action View 6. Package List: Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6): Source: rh-ror50-rubygem-actionpack-5.0.1-2.el6.src.rpm noarch: rh-ror50-rubygem-actionpack-5.0.1-2.el6.noarch.rpm rh-ror50-rubygem-actionpack-doc-5.0.1-2.el6.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6): Source: rh-ror50-rubygem-actionpack-5.0.1-2.el6.src.rpm noarch: rh-ror50-rubygem-actionpack-5.0.1-2.el6.noarch.rpm rh-ror50-rubygem-actionpack-doc-5.0.1-2.el6.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7): Source: rh-ror50-rubygem-actionpack-5.0.1-2.el7.src.rpm noarch: rh-ror50-rubygem-actionpack-5.0.1-2.el7.noarch.rpm rh-ror50-rubygem-actionpack-doc-5.0.1-2.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4): Source: rh-ror50-rubygem-actionpack-5.0.1-2.el7.src.rpm noarch: rh-ror50-rubygem-actionpack-5.0.1-2.el7.noarch.rpm rh-ror50-rubygem-actionpack-doc-5.0.1-2.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5): Source: rh-ror50-rubygem-actionpack-5.0.1-2.el7.src.rpm noarch: rh-ror50-rubygem-actionpack-5.0.1-2.el7.noarch.rpm rh-ror50-rubygem-actionpack-doc-5.0.1-2.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6): Source: rh-ror50-rubygem-actionpack-5.0.1-2.el7.src.rpm noarch: rh-ror50-rubygem-actionpack-5.0.1-2.el7.noarch.rpm rh-ror50-rubygem-actionpack-doc-5.0.1-2.el7.noarch.rpm Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7): Source: rh-ror50-rubygem-actionpack-5.0.1-2.el7.src.rpm noarch: rh-ror50-rubygem-actionpack-5.0.1-2.el7.noarch.rpm rh-ror50-rubygem-actionpack-doc-5.0.1-2.el7.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2019-5418 https://access.redhat.com/security/cve/CVE-2019-5419 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is. More contact details at https://access.redhat.com/security/team/contact Copyright 2019 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBXNkw5dzjgjWX9erEAQhiHBAAiUDdS68e/pkQQ4YDneLBLdLOmZaoPZqa E8BkpklNIsYBx3x6PUiky9PDkdd8dkHO9f4I1dl55irKlqrg1hKJUBMsm2LMHUTf o7/QXoHIRF8HP995GBNmpChGAbE9CtZI8VNbZh6kgNmpeCAYRwoBI7e6TSmJ6aUj LzZpw3dvy8cUNkuBJiV/4ZDe+a0s/X0BS91OlCQ7J8DeXyNlFddTNT2ic9nwmmLy ajvvexoSr1tVaMAeeotfuGYxFOUVAzuVgH5fIi5NwpHQn86alyqjYr+e1XQsLOGH Gf7Njb5+aenqjzXXjrUoplUJEMCD885mdECTsM3WwFRaVBt+F5LuO+EBN034nWp9 r8EYxWO0+f9IDTUV7ndCDpmCz4EnfBL7IR2EwzXtXKyBQdoBrEXZW//gf/o+0xMg 7U+omBp4JuC6lNwlhQY2ieCY8Aq/DttP6M1tDh0kT7uQNIk9Fmz0qVH9aTkRS6T3 +/3qglkQN58WY2woQoU5hetcjdGf8kCpHuzj57PbgHq7lJuUH5jEC8CJOTuD1tw+ 0CtYU41Yw5SI5//54DKU/eSK0bAzHlgTAWmhxJsiSkQnWJHiw2+tt0ELNCxh/LxR UK1JPY++4jWQCp8iGioEmDAcSSRKYBb1O59OwH5weQ7/IwCzDLu2qnWLIPdxbLQI p60qNG9Boyk=Vfif -----END PGP SIGNATURE----- -- RHSA-announce mailing list This email address is being protected from spambots. You need JavaScript enabled to view it.
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
Ruby on Rails is a model-view-controller (MVC) framework for web
application development. Action Pack implements the controller and the view
components.
Security Fix(es):
* rubygem-actionpack: render file directory traversal in Action View
(CVE-2019-5418)
* rubygem-actionpack: denial of service vulnerability in Action View
(CVE-2019-5419)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
https://access.redhat.com/security/cve/CVE-2019-5418 https://access.redhat.com/security/cve/CVE-2019-5419 https://access.redhat.com/security/updates/classification#important
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6):
Source:
rh-ror50-rubygem-actionpack-5.0.1-2.el6.src.rpm
noarch:
rh-ror50-rubygem-actionpack-5.0.1-2.el6.noarch.rpm
rh-ror50-rubygem-actionpack-doc-5.0.1-2.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6):
Source:
rh-ror50-rubygem-actionpack-5.0.1-2.el6.src.rpm
noarch:
rh-ror50-rubygem-actionpack-5.0.1-2.el6.noarch.rpm
rh-ror50-rubygem-actionpack-doc-5.0.1-2.el6.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7):
Source:
rh-ror50-rubygem-actionpack-5.0.1-2.el7.src.rpm
noarch:
rh-ror50-rubygem-actionpack-5.0.1-2.el7.noarch.rpm
rh-ror50-rubygem-actionpack-doc-5.0.1-2.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4):
Source:
rh-ror50-rubygem-actionpack-5.0.1-2.el7.src.rpm
noarch:
rh-ror50-rubygem-actionpack-5.0.1-2.el7.noarch.rpm
rh-ror50-rubygem-actionpack-doc-5.0.1-2.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5):
Source:
rh-ror50-rubygem-actionpack-5.0.1-2.el7.src.rpm
noarch:
rh-ror50-rubygem-actionpack-5.0.1-2.el7.noarch.rpm
rh-ror50-rubygem-actionpack-doc-5.0.1-2.el7.noarch.rpm
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6):
Source:
Read the Full Advisory
An update for rh-ror50-rubygem-actionpack is now available for Red HatSoftware Collections.Red Hat Product Security has rated this update as having a security impactof Important. A Common Vulnerability Scoring System (CVSS) base score,which gives a detailed severity rating, is available for each vulnerabilityfrom the CVE link(s) in the References section.
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server (v. 7) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.4) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.5) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Server EUS (v. 7.6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 6) - noarch
Red Hat Software Collections for Red Hat Enterprise Linux Workstation (v. 7) - noarch
1689159 - CVE-2019-5418 rubygem-actionpack: render file directory traversal in Action View
1689160 - CVE-2019-5419 rubygem-actionpack: denial of service vulnerability in Action View
Get the latest Linux and open source security news straight to your inbox.