Oval Definition:oval:com.redhat.rhsa:def:20131441
Revision Date:2013-10-17Version:636
Title:RHSA-2013:1441: rubygems security update (Moderate)
Description:RubyGems is the Ruby standard for publishing and managing third-party libraries.

  • It was found that RubyGems did not verify SSL connections. This could lead to man-in-the-middle attacks. (CVE-2012-2126)

  • It was found that, when using RubyGems, the connection could be redirected from HTTPS to HTTP. This could lead to a user believing they are installing a gem via HTTPS, when the connection may have been silently downgraded to HTTP. (CVE-2012-2125)

  • It was discovered that the rubygems API validated version strings using an unsafe regular expression. An application making use of this API to process a version string from an untrusted source could be vulnerable to a denial of service attack through CPU exhaustion. (CVE-2013-4287)

    Red Hat would like to thank Rubygems upstream for reporting CVE-2013-4287. Upstream acknowledges Damir Sharipov as the original reporter.

    All rubygems users are advised to upgrade to this updated package, which contains backported patches to correct these issues.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2012-2125
    CVE-2012-2125
    CVE-2012-2126
    CVE-2012-2126
    CVE-2013-4287
    CVE-2013-4287
    RHSA-2013:1441
    RHSA-2013:1441-01
    RHSA-2013:1441-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND rubygems is earlier than 0:1.3.7-4.el6_4
  • AND rubygems is signed with Red Hat redhatrelease2 key
  • BACK