SCIENTIFIC-LINUX-ERRATA Archives

December 2015

SCIENTIFIC-LINUX-ERRATA@LISTSERV.FNAL.GOV

Options: Use Monospaced Font
Show Text Part by Default
Show All Mail Headers

Message: [<< First] [< Prev] [Next >] [Last >>]
Topic: [<< First] [< Prev] [Next >] [Last >>]
Author: [<< First] [< Prev] [Next >] [Last >>]

Print Reply
Subject:
From:
Pat Riehecky <[log in to unmask]>
Reply To:
Date:
Mon, 21 Dec 2015 23:13:12 +0000
Content-Type:
text/plain
Parts/Attachments:
text/plain (26 lines)
Synopsis:          Moderate: rubygem-bundler and rubygem-thor security, bug fix, and enhancement update
Advisory ID:       SLSA-2015:2180-7
Issue Date:        2015-11-19
CVE Numbers:       CVE-2013-0334
--

A flaw was found in the way Bundler handled gems available from multiple
sources. An attacker with access to one of the sources could create a
malicious gem with the same name, which they could then use to trick a
user into installing, potentially resulting in execution of code from the
attacker-supplied malicious gem. (CVE-2013-0334)

Bundler has been upgraded to upstream version 1.7.8 and Thor has been
upgraded to upstream version 1.19.1, both of which provide a number of bug
fixes and enhancements over the previous versions.
--

SL7
  noarch
    rubygem-bundler-1.7.8-3.el7.noarch.rpm
    rubygem-thor-0.19.1-1.el7.noarch.rpm
    rubygem-bundler-doc-1.7.8-3.el7.noarch.rpm
    rubygem-thor-doc-0.19.1-1.el7.noarch.rpm

- Scientific Linux Development Team

ATOM RSS1 RSS2