Ispravljeno je nekoliko nedostataka u programskom paketu rubygem-activemodel. Radi se o paketu koji pruža podršku u razvoju klasa u Rails okruženju. Jedan od otkrivenih nedostataka je XSS ranjivost u "mail_to_helper", a rezultira umetanjem proizvoljnog HTML i skriptnog koda pomoću posebno oblikovanih "name" i "email" vrijednosti. Ostali nedostaci su posljedica nedovoljnih provjera ulaznih parametara u nekoliko programskih komponenti, a mogu se iskoristiti za zaobilaženje postavljenih ograničenja, umetanje proizvoljnog SQL koda i CSRF napad. Korisnici se potiču na korištenje najnovije inačice.

Fedora Update Notification
2011-03-30 02:21:01

Name        : rubygem-activemodel
Product     : Fedora 15
Version     : 3.0.5
Release     : 1.fc15
URL         :
Summary     : A toolkit for building modeling frameworks
Description :
Rich support for attributes, callbacks, validations, observers,
serialization, internationalization, and testing. It provides a known
set of interfaces for usage in model classes. It also helps building
custom ORMs for use outside of the Rails framework.

Update Information:

Update to the Rails 3.0.5

  [ 1 ] Bug #679351 - CVE-2011-0449 rubygem-actionpack: Intended access
restriction bypass via crafted action name, when case-insensitive filesystem is
  [ 2 ] Bug #679343 - CVE-2011-0448 rubygem-activerecord: SQL injection attacks
via a non-numeric arguments
  [ 3 ] Bug #677631 - CVE-2011-0447 rubygem-actionpack: CSRF flaws due improper
validation of HTTP headers containing X-Requested-With header
  [ 4 ] Bug #677626 - CVE-2011-0446 rubygem-actionpack: Multiple XSS flaws via
crafted name or email value in the mail_to_helper

This update can be installed with the "yum" update program.  Use 
su -c 'yum update rubygem-activemodel' at the command line.
For more information, refer to "Managing Software with yum",
available at

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
package-announce mailing list
Ova e-mail adresa je zaštićena od spambota. Potrebno je omogućiti JavaScript da je vidite.

Idi na vrh