Bugzilla – Bug 876714
VUL-0: CVE-2014-0130: rubygem-actionpack: directory traversal issue
Last modified: 2015-07-23 09:31:14 UTC
rh#1095105 References: https://bugzilla.redhat.com/show_bug.cgi?id=1095105 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0130
bugbot adjusting priority
Created attachment 590629 [details] patch for 3.2.x
Affected packages: SLE-11-SP3: rubygem-rails SLE-10-SP3-TERADATA: rubygem-actionpack
This is an autogenerated message for OBS integration: This bug (876714) was mentioned in https://build.opensuse.org/request/show/234738 12.3 / rubygem-actionpack-3_2 https://build.opensuse.org/request/show/234739 13.1 / rubygem-actionpack-3_2
MaintenanceTracker-57474
Created attachment 591874 [details] proposal fix for 2.3
I've attached a proposal for fixing 2.3. However I am having some difficulties to setup a test environment.
openSUSE-SU-2014:0718-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 876714 CVE References: CVE-2014-0130 Sources used: openSUSE 13.1 (src): rubygem-actionpack-3_2-3.2.13-2.24.1
openSUSE-SU-2014:0720-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 876714 CVE References: CVE-2014-0130 Sources used: openSUSE 12.3 (src): rubygem-actionpack-3_2-3.2.12-1.28.1
Update released for: rubygem-actionpack-3_2, rubygem-actionpack-3_2-doc Products: SLE-SLMS 1.3 (x86_64) SLE-STUDIOONSITE 1.3 (x86_64) SLE-WEBYAST 1.3 (i386, ia64, ppc64, s390x, x86_64)
SUSE-SU-2014:0756-1: An update that solves three vulnerabilities and has one errata is now available. Category: security (moderate) Bug References: 864431,864433,864873,876714 CVE References: CVE-2014-0081,CVE-2014-0082,CVE-2014-0130 Sources used: WebYaST 1.3 (src): rubygem-actionpack-3_2-3.2.12-0.15.1 SUSE Studio Onsite 1.3 (src): rubygem-actionpack-3_2-3.2.12-0.15.1 SUSE Lifecycle Management Server 1.3 (src): rubygem-actionpack-3_2-3.2.12-0.15.1
Update released for: rubygem-actionpack-2_3 Products: SUSE-CLOUD 3.0 (x86_64)
SUSE-SU-2014:0801-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 876714 CVE References: CVE-2014-0130 Sources used: SUSE Cloud 3 (src): rubygem-actionpack-2_3-2.3.17-0.17.1
all packages fixed
resolved, fixed and released.