oss-sec mailing list archives

Re: Ruby CVEs


From: Henri Salo <henri () nerv fi>
Date: Tue, 19 Mar 2013 12:00:19 +0200

On Tue, Mar 19, 2013 at 01:17:11AM -0600, Kurt Seifried wrote:
http://direct.osvdb.org/search?search[vuln_title]=ruby&search[text_type]=titles


===================
These 4 are all the ";" URL parsing issues ny larry0 () me com
===================
http://direct.osvdb.org/show/osvdb/91450
command_wrap gem

http://direct.osvdb.org/show/osvdb/91232
fastreader gem

http://direct.osvdb.org/show/osvdb/91231
MiniMagic gem

http://direct.osvdb.org/show/osvdb/91230
Curl gem


===================
http://direct.osvdb.org/show/osvdb/90717
fileutils - has CVE-2013-2516 - where did this come from (I assume
Mitre?)? Does it cover just this issue or the next 3?
===================

http://direct.osvdb.org/show/osvdb/90718
fileutils gem
code exec

http://direct.osvdb.org/show/osvdb/90716
fileutils gem
dir creation

http://direct.osvdb.org/show/osvdb/90715
fileutils gem
tmp file creation
===================

http://direct.osvdb.org/show/osvdb/90206
typecasting - mysql/etc. - we probably need another long email from
steve on how to handle this =)

http://direct.osvdb.org/show/osvdb/89612
gemcutter - Psych YAML parse - do we assign a vuln for psych?

http://direct.osvdb.org/show/osvdb/90946
libxml2 entity expansion *** see Steven's long posting, I need to
figure this out yet.

Also am I missing anything else?

- -- 
Kurt Seifried Red Hat Security Response Team (SRT)
PGP: 0x5E267993 A90B F995 7350 148F 66BF 7554 160D 4553 5E26 7993

Please note that in private email Larry said he will request CVEs for these
security vulnerabilities. Adding Larry as CC so he can tell us if he already did
that and if he didn't we can assign those in this thread.

---
Henri Salo


Current thread: