MGASA-2014-0303

Source
https://advisories.mageia.org/MGASA-2014-0303.html
Import Source
https://advisories.mageia.org/MGASA-2014-0303.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2014-0303
Related
Published
2014-07-26T13:09:43Z
Modified
2014-07-26T13:09:38Z
Summary
Updated ruby-actionpack packages fix security issues
Details

Updated ruby-actionpack and ruby-activerecord packages fix security vulnerabilities:

Directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb in the implicit-render implementation in Ruby on Rails before 4.0.5, when certain route globbing configurations are enabled, allows remote attackers to read arbitrary files via a crafted request (CVE-2014-0130).

PostgreSQL supports a number of unique data types which are not present in other supported databases. A bug in the SQL quoting code in ActiveRecord in Ruby on Rails before 4.0.7 can allow an attacker to inject arbitrary SQL using carefully crafted values (CVE-2014-3483).

The associated Ruby on Rails packages have been updated to version 4.0.8, to address these and other issues.

References
Credits

Affected packages

Mageia:4 / ruby-actionmailer

Package

Name
ruby-actionmailer
Purl
pkg:rpm/mageia/ruby-actionmailer?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.8-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-actionpack

Package

Name
ruby-actionpack
Purl
pkg:rpm/mageia/ruby-actionpack?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.8-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-activemodel

Package

Name
ruby-activemodel
Purl
pkg:rpm/mageia/ruby-activemodel?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.8-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-activerecord

Package

Name
ruby-activerecord
Purl
pkg:rpm/mageia/ruby-activerecord?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.8-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-activesupport

Package

Name
ruby-activesupport
Purl
pkg:rpm/mageia/ruby-activesupport?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.8-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-rails

Package

Name
ruby-rails
Purl
pkg:rpm/mageia/ruby-rails?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.8-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / ruby-railties

Package

Name
ruby-railties
Purl
pkg:rpm/mageia/ruby-railties?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.0.8-1.mga4

Ecosystem specific

{
    "section": "core"
}