Sign Up
Log In
Log In
or
Sign Up
Places
All Projects
Status Monitor
Collapse sidebar
SUSE:SLE-12-SP1:Update
patchinfo.5663
_patchinfo
Overview
Repositories
Revisions
Requests
Users
Attributes
Meta
File _patchinfo of Package patchinfo.5663
<patchinfo incident="5663"> <issue id="1055962" tracker="bnc">update rails to latest stable release to include security fixes</issue> <issue id="322795" tracker="fate"/> <issue id="2016-2098" tracker="cve"/> <issue id="2016-6316" tracker="cve"/> <issue id="2016-6317" tracker="cve"/> <issue id="968849" tracker="bnc">CVE-2016-2098: rubygem-actionpack: Possible remote code execution vulnerability in Action Pack</issue> <issue id="993302" tracker="bnc">CVE-2016-6316: rubygem-actionview-*: Possible XSS Vulnerability in Action View</issue> <issue id="993313" tracker="bnc">CVE-2016-6317:: Unsafe Query Generation Risk in Active Record</issue> <category>security</category> <rating>moderate</rating> <packager>rsalevsky</packager> <description>This update brings version 4.2.9 of the Ruby on Rails stack to provide the latest fixes and improvements from upstream. The following security issues have been fixed by upstream: rubygem-actionpack-4_2 - CVE-2016-2098: Action Pack in Ruby on Rails allowed remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method (bsc#968849). rubygem-activerecord-4_2 - CVE-2016-6317: Action Record did not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allowed remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request (bsc#993313). rubygem-actionview-4_2 - CVE-2016-6316: Cross-site scripting (XSS) vulnerability in Action View might have allowed remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers (bsc#993302). Additionally, the following packages have been updated to version 4.2.9: - rubygem-rails-4_2 - rubygem-railties-4_2 - rubygem-activesupport-4_2 - rubygem-activerecord-4_2 - rubygem-activejob-4_2 - rubygem-actionview-4_2 - rubygem-actionpack-4_2 - rubygem-actionmailer-4_2</description> <summary>Security update for the Ruby on Rails stack</summary> </patchinfo>
Locations
Projects
Search
Status Monitor
Help
OpenBuildService.org
Documentation
API Documentation
Code of Conduct
Contact
Support
@OBShq
Terms
openSUSE Build Service is sponsored by
The Open Build Service is an
openSUSE project
.
Sign Up
Log In
Places
Places
All Projects
Status Monitor