Novom inačicom je ispravljeno nekoliko ranjivosti programskog paketa rubygem-rails. Radi se o radnom okruženju za razvoj web aplikacija. Ranjivosti su posljedica nedovoljne provjere ulaznih parametara i nepravilno postavljenih ograničenja, te XSS ranjivosti u "mail_to_helper". Ranjivosti mogu iskoristiti udaljeni napadači za zaobilaženje postavljenih ograničenja, umetanje proizvoljnog SQL, skriptnog ili HTML programskog koda te CSRF (eng. cross-site request forgery) napad. Korisnicima se preporuča korištenje nadogradnje.

Fedora Update Notification
2011-03-30 02:21:01

Name        : rubygem-rails
Product     : Fedora 15
Version     : 3.0.5
Release     : 2.fc15
URL         :
Summary     : Web-application framework
Description :
Rails is a framework for building web-application using CGI, FCGI, mod_ruby,
or WEBrick on top of either MySQL, PostgreSQL, SQLite, DB2, SQL Server, or
Oracle with eRuby- or Builder-based templates.

Update Information:

Update to the Rails 3.0.5

  [ 1 ] Bug #679351 - CVE-2011-0449 rubygem-actionpack: Intended access
restriction bypass via crafted action name, when case-insensitive filesystem is
  [ 2 ] Bug #679343 - CVE-2011-0448 rubygem-activerecord: SQL injection attacks
via a non-numeric arguments
  [ 3 ] Bug #677631 - CVE-2011-0447 rubygem-actionpack: CSRF flaws due improper
validation of HTTP headers containing X-Requested-With header
  [ 4 ] Bug #677626 - CVE-2011-0446 rubygem-actionpack: Multiple XSS flaws via
crafted name or email value in the mail_to_helper

This update can be installed with the "yum" update program.  Use 
su -c 'yum update rubygem-rails' at the command line.
For more information, refer to "Managing Software with yum",
available at

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.

Idi na vrh