oss-sec mailing list archives
Re: Ruby 1.9.2-p290 WEBrick::HTTPRequest X-Forwarded-*
From: Kurt Seifried <kseifried () redhat com>
Date: Tue, 18 Oct 2011 08:20:11 -0600
Matthias Weckbecker <mweckbecker () suse de> wrote:
https://redmine.ruby-lang.org/issues/5418 Can we get a CVE for this please?I think this is already covered by CVE-2011-3187.
Sort of, similar issue (lack of input verification), but it's in a different code base, which traditionally means a different CVE is assigned. Also CVE-2011-3187 was fixed in Ruby on Rails 3.0.10, this new issue is still unfixed in Ruby. -- -Kurt Seifried / Red Hat Security Response Team
Current thread:
- Ruby 1.9.2-p290 WEBrick::HTTPRequest X-Forwarded-* Kurt Seifried (Oct 12)
- Re: Ruby 1.9.2-p290 WEBrick::HTTPRequest X-Forwarded-* Matthias Weckbecker (Oct 18)
- Re: Ruby 1.9.2-p290 WEBrick::HTTPRequest X-Forwarded-* Kurt Seifried (Oct 18)
- Re: Ruby 1.9.2-p290 WEBrick::HTTPRequest X-Forwarded-* Josh Bressers (Oct 18)
- Re: Ruby 1.9.2-p290 WEBrick::HTTPRequest X-Forwarded-* Matthias Weckbecker (Oct 18)