Multiple vulnerabilities in Ruby
Bug #257122 reported by
Mark Painter
Affects | Status | Importance | Assigned to | Milestone | |
---|---|---|---|---|---|
ruby1.8 (Ubuntu) |
Fix Released
|
Undecided
|
Unassigned | ||
Dapper |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Feisty |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Gutsy |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Hardy |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Intrepid |
Fix Released
|
Undecided
|
Unassigned | ||
ruby1.9 (Ubuntu) |
Fix Released
|
Undecided
|
Jamie Strandboge | ||
Dapper |
Won't Fix
|
Undecided
|
Unassigned | ||
Feisty |
Won't Fix
|
Undecided
|
Unassigned | ||
Gutsy |
Won't Fix
|
Undecided
|
Unassigned | ||
Hardy |
Won't Fix
|
Undecided
|
Unassigned | ||
Intrepid |
Fix Released
|
Undecided
|
Jamie Strandboge |
Bug Description
Some vulnerabilities have been reported in Ruby, which can be exploited by malicious people to bypass certain security restrictions, cause a DoS (Denial of Service), and conduct spoofing attacks.
http://
Vulnerable versions
1.8 series
* 1.8.5 and all prior versions
* 1.8.6-p286 and all prior versions
* 1.8.7-p71 and all prior versions
1.9 series
* r18423 and all prior revisions
Changed in ruby1.8: | |
assignee: | nobody → jdstrand |
status: | New → Confirmed |
assignee: | jdstrand → nobody |
status: | Confirmed → Fix Released |
assignee: | nobody → jdstrand |
status: | New → Confirmed |
assignee: | nobody → jdstrand |
status: | New → Confirmed |
assignee: | nobody → jdstrand |
status: | New → Confirmed |
assignee: | nobody → jdstrand |
status: | New → Confirmed |
Changed in ruby1.9: | |
assignee: | nobody → jdstrand |
Changed in ruby1.8: | |
status: | Confirmed → In Progress |
status: | Confirmed → In Progress |
status: | Confirmed → In Progress |
status: | Confirmed → In Progress |
To post a comment you must log in.
I hate to be a nag, but this package is in main, and it's been a month, and well, the SABDFL seems to think Ubuntu has a good track record with security fixes...
"Well we have a better security track record than Red Hat, we do that by focusing very hard on security, making sure the updates are available as fast as possible on Ubuntu, independent studies have generally ranked Ubuntu number one."
http:// derstandard. at/?url= /?id=3413801 lwn.net/ Articles/ 290156/
http://
Any chance it can get fixed?