Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

Slackware 14.0 2013-136-02 Critical: Ruby System Call Threat

slackware
Calendar Grey May 16, 2013
Scroller Slackware
Recent Ruby libraries for Slackware tackle vital vulnerabilities in system functions. Ensure to apply updates for secure usage.
New ruby packages are available for Slackware 13.1, 13.37, 14.0, and -current to fix a security issue

Summary

Here are the details from the Slackware 14.0 ChangeLog: patches/packages/ruby-1.9.3_p429-i486-1_slack14.0.txz: Upgraded. This update fixes a security issue in DL and Fiddle included in Ruby where tainted strings can be used by system calls regardless of the $SAFE level setting. For more information, see: https://www.cve.org/CVERecord?id=CVE-2013-2065 https://www.ruby-lang.org/en/news/2013/05/14/taint-bypass-dl-fiddle-cve-2013-2065/ (* Security fix *)

Where Find New Packages

Thanks to the friendly folks at the OSU Open Source Lab (https://osuosl.org/) for donating FTP and rsync hosting to the Slackware project! :-)
Also see the "Get Slack" section on http://www.slackware.com/ for additional mirror sites near you.
Updated package for Slackware 13.1:
Updated package for Slackware x86_64 13.1:
Updated package for Slackware 13.37:
Updated package for Slackware x86_64 13.37:
Updated package for Slackware 14.0:
Updated package for Slackware x86_64 14.0:
Updated package for Slackware -current:
Updated package for Slackware x86_64 -current:

MD5 Signatures

Slackware 13.1 package: f6749a02556c8d36ea778efd7c648e38 ruby-1.9.3_p429-i486-1_slack13.1.txz
Slackware x86_64 13.1 package: 57cebcb0da090e6359c99997103b07eb ruby-1.9.3_p429-x86_64-1_slack13.1.txz
Slackware 13.37 package: fd110a0d6eba27e8d3841448e5cfcce7 ruby-1.9.3_p429-i486-1_slack13.37.txz
Slackware x86_64 13.37 package: 7102c181ea158525497bea4e3330c348 ruby-1.9.3_p429-x86_64-1_slack13.37.txz
Slackware 14.0 package: 7ee54d593ead24ca3ec2f7147c938f28 ruby-1.9.3_p429-i486-1_slack14.0.txz
Slackware x86_64 14.0 package: 9a7e5786145827083db2001b8ef3d629 ruby-1.9.3_p429-x86_64-1_slack14.0.txz
Slackware -current package: 5f381efa8c16989fec3432a286ce85c5 d/ruby-1.9.3_p429-i486-1.txz
Slackware x86_64 -current package: f662bb06aca7166f4b8159ce839c7f0c d/ruby-1.9.3_p429-x86_64-1.txz

Severity
critical
Lowest
Low
Medium
High
Critical

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Installation Instructions

Installation instructions: Upgrade the package as root: # upgradepkg ruby-1.9.3_p429-i486-1_slack14.0.txz