ruby1.8 1.8.6.36-1ubuntu3.3 source package in Ubuntu

Changelog

ruby1.8 (1.8.6.36-1ubuntu3.3) gutsy-security; urgency=low

  * SECURITY UPDATE: denial of service via resource exhaustion in the REXML
    module (LP: #261459)
    - debian/patches/103_CVE-2008-3790.dpatch: adjust rexml/document.rb and
      rexml/entity.rb to use expansion limits
    - CVE-2008-3790
  * SECURITY UPDATE: integer overflow in rb_ary_fill may cause denial of
    service (LP: #246818)
    - debian/patches/104_CVE-2008-2376.dpatch: adjust array.c to properly
      check argument length
    - CVE-2008-2376
  * SECURITY UPDATE: denial of service via multiple long requests to a Ruby
    socket
    - debian/patches/105_CVE-2008-3443.dpatch: adjust regex.c to not use ruby
      managed memory and check for allocation failures
    - CVE-2008-3443
  * SECURITY UPDATE: denial of service via crafted HTTP request (LP: #257122)
    - debian/patches/106_CVE-2008-3656.dpatch: update webrick/httputils.rb to
      properly check paths ending with '.'
    - CVE-2008-3656
  * SECURITY UPDATE: predictable transaction id and source port for DNS
    requests (separate vulnerability from CVE-2008-1447)
    - debian/patches/107_CVE-2008-3905.dpatch: adjust resolv.rb to use
      SecureRandom for transaction id and source port
    - CVE-2008-3905
  * SECURITY UPDATE: safe level bypass via DL.dlopen
    - debian/patches/108_CVE-2008-3657.dpatch: adjust rb_str_to_ptr and
      rb_ary_to_ptr in ext/dl/dl.c and rb_dlsym_call in ext/dl/sym.c to
      propogate taint and check taintness of DLPtrData
    - CVE-2008-3657
  * SECURITY UPDATE: safe level bypass via multiple vectors
    - debian/patches/109_CVE-2008-3655.dpatch: use rb_secure(4) in variable.c
      and syslog.c, check for secure level 3 or higher in eval.c and make
      sure PROGRAM_NAME can't be modified
    - CVE-2008-3655

 -- Jamie Strandboge <email address hidden>   Thu, 09 Oct 2008 08:47:35 -0500

Upload details

Uploaded by:
Jamie Strandboge
Uploaded to:
Gutsy
Original maintainer:
Ubuntu Development Team
Architectures:
any
Section:
interpreters
Urgency:
Low Urgency

See full publishing history Publishing

Series Pocket Published Component Section

Downloads

File Size SHA-256 Checksum
ruby1.8_1.8.6.36.orig.tar.gz 4.3 MiB 1a9db5f4720a7023d9ecfaa6c4128ecb5f8cd59460744fb4b5f3b64ed3786935
ruby1.8_1.8.6.36-1ubuntu3.3.diff.gz 53.6 KiB e0fd93c562fbd456eeee27849f2dace4fac98ef9abeb4fc02579545437a932d4
ruby1.8_1.8.6.36-1ubuntu3.3.dsc 1.1 KiB c3e74a11216a5001821e840b7dbd9347a03b5c4767700b467ca22534447c1f5d

View changes file

Binary packages built by this source

irb1.8: No summary available for irb1.8 in ubuntu gutsy.

No description available for irb1.8 in ubuntu gutsy.

libdbm-ruby1.8: No summary available for libdbm-ruby1.8 in ubuntu gutsy.

No description available for libdbm-ruby1.8 in ubuntu gutsy.

libgdbm-ruby1.8: No summary available for libgdbm-ruby1.8 in ubuntu gutsy.

No description available for libgdbm-ruby1.8 in ubuntu gutsy.

libopenssl-ruby1.8: No summary available for libopenssl-ruby1.8 in ubuntu gutsy.

No description available for libopenssl-ruby1.8 in ubuntu gutsy.

libreadline-ruby1.8: No summary available for libreadline-ruby1.8 in ubuntu gutsy.

No description available for libreadline-ruby1.8 in ubuntu gutsy.

libruby1.8: No summary available for libruby1.8 in ubuntu gutsy.

No description available for libruby1.8 in ubuntu gutsy.

libruby1.8-dbg: No summary available for libruby1.8-dbg in ubuntu gutsy.

No description available for libruby1.8-dbg in ubuntu gutsy.

libtcltk-ruby1.8: No summary available for libtcltk-ruby1.8 in ubuntu gutsy.

No description available for libtcltk-ruby1.8 in ubuntu gutsy.

rdoc1.8: No summary available for rdoc1.8 in ubuntu gutsy.

No description available for rdoc1.8 in ubuntu gutsy.

ri1.8: No summary available for ri1.8 in ubuntu gutsy.

No description available for ri1.8 in ubuntu gutsy.

ruby1.8: No summary available for ruby1.8 in ubuntu gutsy.

No description available for ruby1.8 in ubuntu gutsy.

ruby1.8-dev: No summary available for ruby1.8-dev in ubuntu gutsy.

No description available for ruby1.8-dev in ubuntu gutsy.

ruby1.8-elisp: No summary available for ruby1.8-elisp in ubuntu gutsy.

No description available for ruby1.8-elisp in ubuntu gutsy.

ruby1.8-examples: No summary available for ruby1.8-examples in ubuntu gutsy.

No description available for ruby1.8-examples in ubuntu gutsy.