Bug 961066 - CVE-2009-3086 rubygem-actionpack: Message digest forgery [epel-5]
Summary: CVE-2009-3086 rubygem-actionpack: Message digest forgery [epel-5]
Alias: None
Product: Fedora EPEL
Classification: Fedora
Component: rubygem-actionpack
Version: el5
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Michael Stahnke
QA Contact: Fedora Extras Quality Assurance
Whiteboard: fst_owner=jrusnack
Depends On:
Blocks: CVE-2009-3086
TreeView+ depends on / blocked
Reported: 2013-05-08 17:42 UTC by Vincent Danen
Modified: 2015-04-23 14:39 UTC (History)
3 users (show)

Fixed In Version:
Doc Type: Release Note
Doc Text:
Clone Of:
Last Closed: 2015-04-23 14:39:04 UTC
Type: ---

Attachments (Terms of Use)

Comment 2 Vincent Danen 2013-05-08 17:42:51 UTC
epel-5 tracking bug for rubygem-actionpack: see blocks bug list for full details of the security issue(s).

[bug automatically created by: add-tracking-bugs]

Comment 2 Vincent Danen 2013-05-08 17:44:21 UTC
Based on https://bugzilla.redhat.com/show_bug.cgi?id=522162#c3 this was intended to be fixed 3 years ago, however that build never made it to EPEL5; it was deleted:


So this flaw is still present in EPEL5.

Comment 3 Michael Stahnke 2014-10-22 06:23:27 UTC
This is fixed in anything > 2.3.4.

Comment 4 Ján Rusnačko 2015-04-23 14:39:04 UTC
Confirming this is fixed in rubygem-activesupport-2.3.18-1.el5.noarch currently shipped in EPEL 5.

Closing ERRATA.

