Multiple vulnerabilities in Ruby may lead to a denial of service (DoS) condition or allow execution of arbitrary code.
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ruby1.8 (Debian) |
Fix Released
|
Unknown
|
|||
ruby1.8 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Fix Released
|
High
|
Jamie Strandboge | ||
Feisty |
Fix Released
|
High
|
Jamie Strandboge | ||
Gutsy |
Fix Released
|
High
|
Jamie Strandboge | ||
Hardy |
Fix Released
|
High
|
Jamie Strandboge | ||
Intrepid |
Fix Released
|
Undecided
|
Unassigned | ||
ruby1.9 (Debian) |
Fix Released
|
Unknown
|
|||
ruby1.9 (Ubuntu) |
Fix Released
|
High
|
Jamie Strandboge | ||
Dapper |
Won't Fix
|
High
|
Unassigned | ||
Feisty |
Won't Fix
|
High
|
Unassigned | ||
Gutsy |
Won't Fix
|
High
|
Unassigned | ||
Hardy |
Won't Fix
|
High
|
Unassigned | ||
Intrepid |
Fix Released
|
High
|
Jamie Strandboge |
Bug Description
Binary package hint: ruby1.8
*** Source: http://
Present on Ubuntu Gutsy Gibbon 7.10 (desktop and server)
Impact
With the following vulnerabilities, an attacker can lead to denial of service condition or execute arbitrary code.
* CVE-2008-2662
* CVE-2008-2663
* CVE-2008-2725
* CVE-2008-2726
* CVE-2008-2727
* CVE-2008-2728
* CVE-2008-2664
Vulnerable versions
1.8 series
* 1.8.4 and all prior versions
* 1.8.5-p230 and all prior versions
* 1.8.6-p229 and all prior versions
* 1.8.7-p21 and all prior versions
1.9 series
* 1.9.0-1 and all prior versions
Solution
1.8 series
Please upgrade to 1.8.5-p231, or 1.8.6-p230, or 1.8.7-p22.
* <URL:ftp://ftp.
* <URL:ftp://ftp.
* <URL:ftp://ftp.
1.9 series
Please upgrade to 1.9.0-2.
* <URL:ftp://ftp.
These versions also fix the vulnerability of WEBrick (CVE-2008-1891).
Changed in ruby1.9: | |
importance: | Undecided → High |
status: | New → Triaged |
importance: | Undecided → High |
status: | New → Triaged |
importance: | Undecided → High |
status: | New → Triaged |
importance: | Undecided → High |
status: | New → Triaged |
Changed in ruby1.8: | |
status: | Unknown → Fix Released |
Changed in ruby1.9: | |
status: | Unknown → Fix Released |
Changed in ruby1.8: | |
assignee: | nobody → jdstrand |
assignee: | nobody → jdstrand |
assignee: | nobody → jdstrand |
assignee: | nobody → jdstrand |
Changed in ruby1.9: | |
assignee: | nobody → jdstrand |
assignee: | nobody → jdstrand |
assignee: | nobody → jdstrand |
assignee: | nobody → jdstrand |
Changed in ruby1.8: | |
status: | Fix Released → New |
Changed in ruby1.9: | |
assignee: | jdstrand → nobody |
assignee: | jdstrand → nobody |
assignee: | jdstrand → nobody |
assignee: | jdstrand → nobody |
assignee: | nobody → jdstrand |
importance: | Undecided → High |
status: | New → In Progress |
Changed in ruby1.8: | |
status: | Triaged → In Progress |
status: | Triaged → In Progress |
status: | Triaged → In Progress |
status: | Triaged → In Progress |
Changed in ruby1.9: | |
status: | In Progress → Fix Committed |
Changed in ruby1.8: | |
status: | New → Fix Released |
Changed in ruby1.9 (Ubuntu Dapper): | |
status: | Triaged → Won't Fix |
ruby1.8 is fixed in Intrepid due to a Debian sync.