Bug 605419
Summary: | CVE-2010-0541 Ruby WEBrick javascript injection flaw [fedora-all] | ||
---|---|---|---|
Product: | [Fedora] Fedora | Reporter: | Vincent Danen <vdanen> |
Component: | ruby | Assignee: | Jeroen van Meeuwen <vanmeeuwen+fedora> |
Status: | CLOSED ERRATA | QA Contact: | Fedora Extras Quality Assurance <extras-qa> |
Severity: | low | Docs Contact: | |
Priority: | low | ||
Version: | 13 | CC: | jeremy, mtasaka, tagoh, vanmeeuwen+fedora |
Target Milestone: | --- | Keywords: | Security, SecurityTracking |
Target Release: | --- | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | |||
Fixed In Version: | Doc Type: | Release Note | |
Doc Text: | Story Points: | --- | |
Clone Of: | Environment: | ||
Last Closed: | 2010-08-24 06:10:43 UTC | Type: | --- |
Regression: | --- | Mount Type: | --- |
Documentation: | --- | CRM: | |
Verified Versions: | Category: | --- | |
oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
Cloudforms Team: | --- | Target Upstream Version: | |
Embargoed: | |||
Bug Depends On: | |||
Bug Blocks: | 587731 |
Description
Vincent Danen
2010-06-17 21:22:29 UTC
For F-15/14, I will update ruby to 1.8.7p302 as the fix for this issue is now upstreamed. For F-13/12, backport patch should be applied. F-15/F14: updated to 1.8.7p302 (1.8.7.302-1.fc1?) F-13/12: patch applied (1.8.6.399-6.fc1?) F-15: http://lists.fedoraproject.org/pipermail/devel/2010-August/141410.html F-14: http://lists.fedoraproject.org/pipermail/package-announce/2010-August/046296.html F-13: http://lists.fedoraproject.org/pipermail/package-announce/2010-August/046044.html F-12: http://lists.fedoraproject.org/pipermail/package-announce/2010-August/046013.html All pushed. |