[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248268

 
 

909

 
 

195051

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

openSUSE-SU-2013:0280-1 -- Suse ruby

ID: oval:org.secpod.oval:def:400481Date: (C)2013-04-01   (M)2024-02-19
Class: PATCHFamily: unix




This update updates the RubyOnRails 2.3 stack to 2.3.16. Security and bugfixes were done, foremost: CVE-2013-0333: A JSON sql/code injection problem was fixed. CVE-2012-5664: A SQL Injection Vulnerability in Active Record was fixed. CVE-2012-2695: A SQL injection via nested hashes in conditions was fixed. CVE-2013-0155: Unsafe Query Generation Risk in Ruby on Rails was fixed. CVE-2013-0156: Multiple vulnerabilities in parameter parsing in Action Pack were fixed. CVE-2012-5664: options hashes should only be extracted if there are extra parameters CVE-2012-2695: Fix SQL injection via nested hashes in conditions CVE-2013-0156: Hash.from_xml raises when it encounters type=symbol or type=yaml. Use Hash.from_trusted_xml to parse this XM

Platform:
openSUSE 11.4
Product:
ruby
Reference:
openSUSE-SU-2013:0280-1
CVE-2012-2695
CVE-2012-6496
CVE-2012-6497
CVE-2013-0155
CVE-2013-0156
CVE-2013-0333
CVE    6
CVE-2013-0156
CVE-2013-0333
CVE-2013-0155
CVE-2012-2695
...
CPE    1
cpe:/o:opensuse:opensuse:11.4

© SecPod Technologies