Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

SUSE: 2014:0723-2 Critical: Rubygem-Json Denial Of Service

suse
Calendar Grey April 3, 2013
Scroller Suse
An update from SUSE has been released to fix critical vulnerabilities in rubygem-crack aimed at mitigating risk of denial of service attacks.
An update that fixes one vulnerability is now available

Summary

The Ruby Gem crack has been updated to 0.1.7 and to fix a security issue: * CVE-2013-1800: Multiple xml parsing issues were fixed that could be used by attackers able to inject XML to cause denial of service problems. Security Issue reference: * CVE-2013-0269 Patch Instructions: To install this SUSE Security Update use YaST online_update. Alternatively you can run the command listed for your product: - SUSE Studio Onsite 1.2: zypper in -t patch slestso12-rubygem-crack-7530 - SUSE Studio Extension for System z 1.2: zypper in -t patch slestso12-rubygem-crack-7530 To bring your system up-to-date, use "zypper patch". Package List: - SUSE Studio Onsite 1.2 (x86_64): rubygem-crack-0.1.7-0.5.4 - SUSE Studio Extension for System z 1.2 (s390x):

References

#804721

Cross- CVE-2013-0269

Affected Products:

SUSE Studio Onsite 1.2

SUSE Studio Extension for System z 1.2

https://www.suse.com/security/cve/CVE-2013-0269.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2013:0615-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.