[Technik] [SECURITY] [DSA-1235-1] New ruby1.8 package fix denial of service

Noèl Köthe noel at debian.org
Fri Dec 15 18:03:27 CET 2006


Am Mittwoch, den 13.12.2006, 12:18 +0000 schrieb Steve Kemp:

> Debian Security Advisory DSA-1235-1                  security at debian.org
> http://www.debian.org/security/                               Steve Kemp
> December 13, 2006
> 
> Package        : ruby1.8
> Vulnerability  : Denial of service
> Problem type   : remote
> Debian-specific: no
> CVE Id(s)      : CVE-2006-5467
> Debian Bug     : 398457

ruby1.8 auf pima, pomo, h01, h02, h03 und h04 aktualisiert.

> For the stable distribution (sarge), this problem has been fixed in version
> 1.8.2-7sarge5.

changelog:
ruby1.8 (1.8.2-7sarge5) stable-security; urgency=high

  * Non-matainer upload by the Security Team.
  * Fix a denial of service attack in CGI handling (CVE-2006-6303).
     - Added 905_CVE-2006-6303.patch

 -- Steve Kemp <skx at debian.org>  Tue, 05 Dec 2006 09:34:21 +0000

-- 
Noèl Köthe <noel debian.org>
Debian GNU/Linux, www.debian.org
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 189 bytes
Desc: Dies ist ein digital signierter Nachrichtenteil
Url : /archiv/technik/attachments/20061215/bfee7c8f/attachment.pgp


More information about the Technik mailing list