Jump to content
Compatible Support Forums
Sign in to follow this  
news

[SECURITY] [DLA 603-1] ruby-activesupport-3.2 security update

Recommended Posts

-----BEGIN PGP SIGNED MESSAGE-----

Hash: SHA256

 

Package : ruby-activesupport-3.2

Version : 3.2.6-6+deb7u2

CVE ID : CVE-2015-3227

 

The support and utility classes used by the Rails 3.2 framework allow

remote attackers to cause a denial of service (SystemStackError) via a

large XML document depth.

 

For Debian 7 "Wheezy", these problems have been fixed in version

3.2.6-6+deb7u2.

 

Additionally this upload adds 'active_support/security_utils' that will

be used by ruby-actionpack-3.2 to address CVE-2015-7576.

 

We recommend that you upgrade your ruby-activesupport-3.2 packages.

 

Further information about Debian LTS security advisories, how to apply

these updates to your system and frequently asked questions can be

found at: https://wiki.debian.org/LTS

-----BEGIN PGP SIGNATURE-----

 

iQIcBAEBCAAGBQJXwb7vAAoJEAe4t7DqmBILKpcQALbV8lVf2KNhVhpWxCHxeu9I

G0fF/rSBH2Qzu91zjxW/hOvBodrtYWCjZklA4kaLa6vSs7AU8cSApnOAL8Yiy0Gt

0JE9I3A3Qd7bE1Ag/TKAE+l5Ihggr+GT8jZIe5LhXB0bDSbacSO9P6IKoqWokCBx

s4NJLYhw4S9JEewDMxHG1GdCv4aPpATObkMKiBIdcCRUr/Sn7+COVKQofqCQGHoE

HUe9Lmr03I5KxXJ1RJqWKDTFIbaQO7IDOhiXvg0dYR92kJxP+/zI2+aUy5RsB6KO

62JA8FYQjprpCRSc8sk+OHe04zJhGGUVcLFNiUIHr6UjigNF394iyl2YZKQz8jZr

XlvJd8y+nFYHbwoeBu9i7t/+i6+OTShQ9pTye8RfqtkDKP0cqny+KoIo5O9czGDo

DFa0DlbvZ3raCs4HoHcdm7RcJZaSRsRSJucTeb2Rz3wk4ONQjwJx24WOCmVeezzD

VeBryfvLZwcudW+eHfSCl5Sa6SreIvNxFMKBFu8AvvfKPkqAdhBA2cldgSh8ThkK

Kbmp6oTxLFx534rZj2Xvjo46AeK8NJZY4D3JA/Tu6YYjtdYPwhTqYrt49BvTvf3A

02TZqjGyELyajLWjzfkh+Q2wUS3I57aQzCst2sZssKQiqV255tXi6mAtT4bC5LFD

fxhoN4eZseZZBNpE0jGG

=XFCS

-----END PGP SIGNATURE-----

 

 

 

Share this post


Link to post

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
Sign in to follow this  

×