Bug 13660 - ruby-activerecord new security issue CVE-2014-3482
Summary: ruby-activerecord new security issue CVE-2014-3482
Status: RESOLVED WONTFIX
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 3
Hardware: i586 Linux
Priority: Normal normal
Target Milestone: ---
Assignee: Funda Wang
QA Contact: Sec team
URL: http://lwn.net/Vulnerabilities/605462/
Whiteboard:
Keywords:
Depends on: 12044
Blocks:
  Show dependency treegraph
 
Reported: 2014-07-02 21:45 CEST by David Walser
Modified: 2014-08-20 23:27 CEST (History)
0 users

See Also:
Source RPM: ruby-activerecord-3.2.13-1.mga3.src.rpm
CVE:
Status comment:


Attachments

Description David Walser 2014-07-02 21:45:32 CEST
A security issue fixed upstream has been announced today (July 2):
http://openwall.com/lists/oss-security/2014/07/02/5

The issue is fixed upstream in version 3.2.19.

This should be updated along with the rest of the packages in the rails suite, which would also fix Bug 12044.

Reproducible: 

Steps to Reproduce:
David Walser 2014-07-02 21:45:45 CEST

Depends on: (none) => 12044

Comment 1 David Walser 2014-07-17 21:37:33 CEST
RedHat has issued an advisory for this on July 14:
https://rhn.redhat.com/errata/RHSA-2014-0876.html

URL: (none) => http://lwn.net/Vulnerabilities/605462/

Comment 2 David Walser 2014-08-20 23:27:02 CEST
Ruby on Rails has been dropped in Cauldron and we are unable to support it.

Status: NEW => RESOLVED
Resolution: (none) => WONTFIX


Note You need to log in before you can comment on or make changes to this bug.