List Info

Thread: Ruby vulnerability?




Ruby vulnerability?
user name
2006-07-28 05:03:43
Hi,

FYI, Red Hat released an advisory today about a
vulnerability in Ruby. So
far it doesn't appear in the VuXML, but am I correct in
presuming it will
soon?

htt
ps://rhn.redhat.com/errata/RHSA-2006-0604.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-200
6-3694

cheers,
-- Joel Hatton --
Infrastructure Manager              | Hotline: +61 7 3365
4417
AusCERT - Australia's national CERT | Fax:     +61 7 3365
7031
The University of Queensland        | WWW:    
www.auscert.org.au
Qld 4072 Australia                  | Email:   auscertauscert.org.au
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-secu
rity
To unsubscribe, send any mail to
"freebsd-security-unsubscribefreebsd.org"
Ruby vulnerability?
user name
2006-07-29 16:34:53
On Fri, Jul 28, 2006 at 03:03:43PM +1000, Joel Hatton wrote:
> 
> FYI, Red Hat released an advisory today about a
vulnerability in Ruby. So
> far it doesn't appear in the VuXML, but am I correct
in presuming it will
> soon?
> 

I've added it; thanks for the report.

-- 
Shaun Amott [ PGP: 0x6B387A9A ]
    Scientia Est Potentia.
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-secu
rity
To unsubscribe, send any mail to
"freebsd-security-unsubscribefreebsd.org"
Ruby vulnerability?
user name
2006-07-30 15:47:33
Shaun Amott wrote:
> On Fri, Jul 28, 2006 at 03:03:43PM +1000, Joel Hatton
wrote:
> > 
> > FYI, Red Hat released an advisory today about a
vulnerability in Ruby. So
> > far it doesn't appear in the VuXML, but am I
correct in presuming it will
> > soon?
> > 
> 
> I've added it; thanks for the report.

Hmm, i saw the flaw with "portaudit -Fda"
yesterday, however - today
my ruby isn't shown as vulnerable anymore. Why?

Frank
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-secu
rity
To unsubscribe, send any mail to
"freebsd-security-unsubscribefreebsd.org"
Ruby vulnerability?
user name
2006-07-30 18:13:24
On Sun, 30 Jul 2006 17:47:33 +0200
Frank Steinborn <steinexnognu.de> wrote:

> Shaun Amott wrote:
> > On Fri, Jul 28, 2006 at 03:03:43PM +1000, Joel
Hatton wrote:
> > > 
> > > FYI, Red Hat released an advisory today about
a vulnerability in Ruby. So
> > > far it doesn't appear in the VuXML, but am I
correct in presuming it will
> > > soon?
> > > 
> > 
> > I've added it; thanks for the report.
> 
> Hmm, i saw the flaw with "portaudit -Fda"
yesterday, however - today
> my ruby isn't shown as vulnerable anymore. Why?

I show it as a vulnerability here.  It could be that you may
have
gotten your last update from a server that hasn't caught up
yet.

Try running it again and see if that helps.

Randy

-- 
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-secu
rity
To unsubscribe, send any mail to
"freebsd-security-unsubscribefreebsd.org"
Ruby vulnerability?
user name
2006-07-30 19:11:01
On 2006.07.30 17:47:33 +0200, Frank Steinborn wrote:
> Shaun Amott wrote:
> > On Fri, Jul 28, 2006 at 03:03:43PM +1000, Joel
Hatton wrote:
> > > 
> > > FYI, Red Hat released an advisory today about
a vulnerability in Ruby. So
> > > far it doesn't appear in the VuXML, but am I
correct in presuming it will
> > > soon?
> > > 
> > 
> > I've added it; thanks for the report.
> 
> Hmm, i saw the flaw with "portaudit -Fda"
yesterday, however - today
> my ruby isn't shown as vulnerable anymore. Why?

The database was broken for a bit due to an invalid entry,
try again
now.

-- 
Simon L. Nielsen
_______________________________________________
freebsd-securityfreebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-secu
rity
To unsubscribe, send any mail to
"freebsd-security-unsubscribefreebsd.org"
[1-5]

about | contact  Other archives ( Real Estate discussion Medical topics )