Bug 3289 - [UPDATE REQUEST] [UPSTREAM UPDATE] ruby
: [UPDATE REQUEST] [UPSTREAM UPDATE] ruby
Status: RESOLVED FIXED
Product: Server Bugs
Classification: ROSA Server
Component: Main Packages
: unspecified
: All Linux
: Normal normal
: ---
Assigned To: Andrew Lukoshko
: ROSA Server Bugs
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2013-12-02 12:41 MSK by Andrew Lukoshko
Modified: 2014-01-10 10:43 MSK (History)
1 user (show)

See Also:
RPM Package:
ISO-related:
Bad POT generating:
Upstream:
vladimir.potapov: qa_verified+
andrew.lukoshko: published_server+


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andrew Lukoshko 2013-12-02 12:41:16 MSK
A buffer overflow flaw was found in the way Ruby parsed floating point
numbers from their text representation. If an application using Ruby
accepted untrusted input strings and converted them to floating point
numbers, an attacker able to provide such input could cause the application
to crash or, possibly, execute arbitrary code with the privileges of the
application. (CVE-2013-4164)

http://rhn.redhat.com/errata/RHSA-2013-1764.html

https://abf.rosalinux.ru/build_lists/1451924
https://abf.rosalinux.ru/build_lists/1451925
Comment 1 Vladimir Potapov 2013-12-10 13:37:33 MSK
ruby-1.8.7.352-13.res6
************************** RHEL Advisory **************************
A buffer overflow flaw was found in the way Ruby parsed floating point
numbers from their text representation. If an application using Ruby
accepted untrusted input strings and converted them to floating point
numbers, an attacker able to provide such input could cause the application
to crash or, possibly, execute arbitrary code with the privileges of the
application. (CVE-2013-4164)
*******************************************************************
QA Verified