This update to rubygem-activerecord fixes a SQL injection
caused by mishandling nested parameters . ( CVE-2012-2695
#766792
Cross- CVE-2012-2660 CVE-2012-2661 CVE-2012-2694
CVE-2012-2695
Affected Products:
WebYaST 1.2
SUSE Studio Standard Edition 1.2
SUSE Studio Onsite 1.2
SUSE Studio Extension for System z 1.2
SUSE Linux Enterprise Software Development Kit 11 SP2
https://www.suse.com/security/cve/CVE-2012-2660.html
https://www.suse.com/security/cve/CVE-2012-2661.html
https://www.suse.com/security/cve/CVE-2012-2694.html
https://www.suse.com/security/cve/CVE-2012-2695.html
Get the latest Linux and open source security news straight to your inbox.