Description: | Updated ruby packages that fix a security issue are now available for RedHat Enterprise Linux 4 and 5.This update has been rated as having moderate security impact by the RedHat Security Response Team.Ruby is an extensible, interpreted, object-oriented, scripting language. Ithas features to process text files and to do system management tasks.Vincent Danen reported, that Red Hat Security Advisory RHSA-2008:0897did not properly address a denial of service flaw in the WEBrick (RubyHTTP server toolkit), known as CVE-2008-3656. This flaw allowed aremote attacker to send a specially-crafted HTTP request to a WEBrickserver that would cause the server to use excessive CPU time. Thisupdate properly addresses this flaw. (CVE-2008-4310)All Ruby users should upgrade to these updated packages, which contain acorrect patch that resolves this issue. |