Debian Security Advisory
DSA-2929-1 ruby-actionpack-3.2 -- security update
- Date Reported:
- 16 May 2014
- Affected Packages:
- ruby-actionpack-3.2
- Vulnerable:
- Yes
- Security database references:
- In the Debian bugtracking system: Bug 747382.
In Mitre's CVE dictionary: CVE-2014-0081, CVE-2014-0082, CVE-2014-0130. - More information:
-
Several vulnerabilities were discovered in Action Pack, a component of Ruby on Rails.
- CVE-2014-0081
actionview/lib/action_view/helpers/number_helper.rb contains multiple cross-site scripting vulnerabilities
- CVE-2014-0082
actionpack/lib/action_view/template/text.rb performs symbol interning on MIME type strings, allowing remote denial-of-service attacks via increased memory consumption.
- CVE-2014-0130
A directory traversal vulnerability in actionpack/lib/abstract_controller/base.rb allows remote attackers to read arbitrary files.
For the stable distribution (wheezy), these problems have been fixed in version 3.2.6-6+deb7u2.
We recommend that you upgrade your ruby-actionpack-3.2 packages.
- CVE-2014-0081