An attacker could trick Ruby into trusting a rogue server.. =========================================================================Ubuntu Security Notice USN-1902-1 July 09, 2013 ruby1.8, ruby1.9.1 vulnerability ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 13.04 - Ubuntu 12.10 - Ubuntu 12.04 LTS Summary: An attacker could trick Ruby into trusting a rogue server. Software Description: - ruby1.8: Object-oriented scripting language - ruby1.9.1: Object-oriented scripting language Details: William (B.J.) Snow Orvis discovered that Ruby incorrectly verified the hostname in SSL certificates. An attacker could trick Ruby into trusting a rogue server certificate, which was signed by a trusted certificate authority, to perform a man-in-the-middle attack. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 13.04: libruby1.8 1.8.7.358-7ubuntu1.1 libruby1.9.1 1.9.3.194-8.1ubuntu1.1 ruby1.8 1.8.7.358-7ubuntu1.1 ruby1.9.1 1.9.3.194-8.1ubuntu1.1 Ubuntu 12.10: libruby1.8 1.8.7.358-4ubuntu0.3 libruby1.9.1 1.9.3.194-1ubuntu1.5 ruby1.8 1.8.7.358-4ubuntu0.3 ruby1.9.1 1.9.3.194-1ubuntu1.5 Ubuntu 12.04 LTS: libruby1.8 1.8.7.352-2ubuntu1.3 libruby1.9.1 1.9.3.0-1ubuntu2.7 ruby1.8 1.8.7.352-2ubuntu1.3 ruby1.9.1 1.9.3.0-1ubuntu2.7 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-1902-1 CVE-2013-4073 Package Information: https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.358-7ubuntu1.1 https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.194-8.1ubuntu1.1 https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.358-4ubuntu0.3 https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.194-1ubuntu1.5 https://launchpad.net/ubuntu/+source/ruby1.8/1.8.7.352-2ubuntu1.3 https://launchpad.net/ubuntu/+source/ruby1.9.1/1.9.3.0-1ubuntu2.7 . To protect your Ruby installation on Ubuntu, it’s essential to upgrade. Follow these steps to manage the update efficiently and maintain security.. Ruby Vulnerability, Ubuntu Security, SSL Issues, Man-in-the-Middle Attack. . Severity: Medium. LinuxSecurity.com Team
Moderate: elinks security update. Date: Mon, 11 Feb 2013 14:03:23 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Moderate: elinks on SL5.x, SL6.x i386/x86_64 Synopsis: Moderate: elinks security update Issue Date: 2013-02-11 CVE Numbers: CVE-2012-4545 -- It was found that ELinks performed client credentials delegation during the client-to-server GSS security mechanisms negotiation. A rogue server could use this flaw to obtain the client's credentials and impersonate that client to other servers that are using GSSAPI. (CVE-2012-4545) -- SL5 x86_64 elinks-0.11.1-8.el5_9.x86_64.rpm elinks-debuginfo-0.11.1-8.el5_9.x86_64.rpm i386 elinks-0.11.1-8.el5_9.i386.rpm elinks-debuginfo-0.11.1-8.el5_9.i386.rpm SL6 x86_64 elinks-0.12-0.21.pre5.el6_3.x86_64.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.x86_64.rpm i386 elinks-0.12-0.21.pre5.el6_3.i686.rpm elinks-debuginfo-0.12-0.21.pre5.el6_3.i686.rpm - Scientific Linux Development Team . The recent elinks security update for Scientific Linux is vital for mitigating the risk of credential theft via server impersonation. Users should upgrade now. Elinks Update, Security Advisory, Scientific Linux, Credential Theft, Moderate Severity. . LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.