Oval Definition:oval:com.redhat.rhsa:def:20131764
Revision Date:2013-11-25Version:636
Title:RHSA-2013:1764: ruby security update (Critical)
Description:Ruby is an extensible, interpreted, object-oriented, scripting language. It has features to process text files and to perform system management tasks.

  • A buffer overflow flaw was found in the way Ruby parsed floating point numbers from their text representation. If an application using Ruby accepted untrusted input strings and converted them to floating point numbers, an attacker able to provide such input could cause the application to crash or, possibly, execute arbitrary code with the privileges of the application. (CVE-2013-4164)

    All ruby users are advised to upgrade to these updated packages, which contain a backported patch to correct this issue.
  • Family:unixClass:patch
    Status:Reference(s):CVE-2013-4164
    CVE-2013-4164
    RHSA-2013:1764
    RHSA-2013:1764-00
    RHSA-2013:1764-02
    Platform(s):Red Hat Enterprise Linux 6
    Product(s):
    Definition Synopsis
  • Red Hat Enterprise Linux must be installed
  • OR Package Information
  • Red Hat Enterprise Linux 6 is installed
  • AND
  • ruby is earlier than 0:1.8.7.352-13.el6
  • AND ruby is signed with Red Hat redhatrelease2 key
  • ruby-devel is earlier than 0:1.8.7.352-13.el6
  • AND ruby-devel is signed with Red Hat redhatrelease2 key
  • ruby-docs is earlier than 0:1.8.7.352-13.el6
  • AND ruby-docs is signed with Red Hat redhatrelease2 key
  • ruby-irb is earlier than 0:1.8.7.352-13.el6
  • AND ruby-irb is signed with Red Hat redhatrelease2 key
  • ruby-libs is earlier than 0:1.8.7.352-13.el6
  • AND ruby-libs is signed with Red Hat redhatrelease2 key
  • ruby-rdoc is earlier than 0:1.8.7.352-13.el6
  • AND ruby-rdoc is signed with Red Hat redhatrelease2 key
  • ruby-ri is earlier than 0:1.8.7.352-13.el6
  • AND ruby-ri is signed with Red Hat redhatrelease2 key
  • ruby-static is earlier than 0:1.8.7.352-13.el6
  • AND ruby-static is signed with Red Hat redhatrelease2 key
  • ruby-tcltk is earlier than 0:1.8.7.352-13.el6
  • AND ruby-tcltk is signed with Red Hat redhatrelease2 key
  • BACK