Opened 19 years ago

Closed 19 years ago

Last modified 16 years ago

#1512 closed defect (fixed)

CAN-2005-1992 vulnerability to arbitrary command execution

Reported by: ken@… Owned by: bdubbs@…
Priority: highest Milestone:
Component: BOOK Version: b-6.1-pre1
Severity: major Keywords:
Cc:

Description

Contrary to original reports from distro(s), this vulnerability *does* apply to ruby-1.8.2 which is in both 6.1-pre and svn. There is a fix at http://www.ruby-lang.org/patches/ruby-1.8.2-xmlrpc-ipimethods-fix.diff - this definitely applies to 1.8.2, and it builds and completes 'make test' with it.

Ken

Change History (6)

comment:1 by LFS-User@…, 19 years ago

Milestone: future6.1
Owner: changed from blfs-book@… to Randy McMurchy
rep_platform: PCAll

comment:2 by LFS-User@…, 19 years ago

Status: newassigned

comment:3 by LFS-User@…, 19 years ago

Owner: changed from Randy McMurchy to bdubbs@…
Status: assignednew

Added the installation of the patch to the Ruby instructions

Keeping this bug open until Bruce merges the commit (R4895) to the 6.1 branch.

comment:4 by LFS-User@…, 19 years ago

Status: newassigned

comment:5 by bdubbs@…, 19 years ago

Resolution: fixed
Status: assignedclosed

Merged changes from ruby into 6.1-pre2.

comment:6 by (none), 16 years ago

Milestone: 6.1

Milestone 6.1 deleted

Note: See TracTickets for help on using tickets.