Bug 443829 (CVE-2008-1891)
| Summary: | CVE-2008-1891 ruby: WEBrick CGI source disclosure | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | Tomas Hoger <thoger> |
| Component: | vulnerability | Assignee: | Red Hat Product Security <security-response-team> |
| Status: | CLOSED WONTFIX | QA Contact: | |
| Severity: | low | Docs Contact: | |
| Priority: | low | ||
| Version: | unspecified | CC: | kreilly, tagoh |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| URL: | http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-1891 | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2009-06-10 19:24:37 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 452293, 452294, 452295 | ||
| Bug Blocks: | |||
|
Description
Tomas Hoger
2008-04-23 15:52:48 UTC
This issue only affects systems where Ruby WEBrick is used to serve content from certain filesystems that treat certain file names as identical (e.g. 'file.name.' is same file as 'file.name'). Out of the mentioned filesystems, only FAT in supported by Red Hat Enterprise Linux, but it's unlikely to be used in a real deployments as storage for web content. Ruby packages as shipped in Red Hat Enterprise Linux 2.1 and 3 do not contain WEBrick and therefore are not affected by this problem. Patch applied in ruby SVN trunk: http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=rev&revision=16453 ruby-1.8.6.230-1.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report. ruby-1.8.6.230-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report. ruby-1.8.6.230-1.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report. The risks associated with fixing this flaw outweigh the benefits of the fix. Red Hat does not plan to fix this flaw in Red Hat Enterprise Linux. |