MGASA-2014-0191

Source
https://advisories.mageia.org/MGASA-2014-0191.html
Import Source
https://advisories.mageia.org/MGASA-2014-0191.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0191
Related
Published
2014-04-24T19:02:23Z
Modified
2014-04-24T19:02:03Z
Summary
Updated ruby-rails and associated packages fix multiple vulnerabilities
Details

Updated ruby-activerecord and ruby-actionpack packages fix security vulnerabilities:

There is a data injection vulnerability in Active Record. Specially crafted strings can be used to save data in PostgreSQL array columns that may not be intended (CVE-2014-0080).

There is an XSS vulnerability in the numbertocurrency, numbertopercentage and numbertohuman helpers in Ruby on Rails (CVE-2014-0081).

The associated packages have been updated to version 4.0.3 to fix these issues.

References
Credits

Affected packages

Mageia:4 / ruby-actionmailer

Package

Name
ruby-actionmailer
Purl
pkg:rpm/mageia/ruby-actionmailer?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-actionpack

Package

Name
ruby-actionpack
Purl
pkg:rpm/mageia/ruby-actionpack?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-activemodel

Package

Name
ruby-activemodel
Purl
pkg:rpm/mageia/ruby-activemodel?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-activerecord

Package

Name
ruby-activerecord
Purl
pkg:rpm/mageia/ruby-activerecord?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-activesupport

Package

Name
ruby-activesupport
Purl
pkg:rpm/mageia/ruby-activesupport?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-rails

Package

Name
ruby-rails
Purl
pkg:rpm/mageia/ruby-rails?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-railties

Package

Name
ruby-railties
Purl
pkg:rpm/mageia/ruby-railties?arch=source&distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.3-1.mga4

Ecosystem specific

{
    "section": "core"
}