--------------------------------------------------------------------------------
Fedora Update Notification
FEDORA-2009-9799
2009-09-24 04:13:14
--------------------------------------------------------------------------------

Name        : rubygem-activesupport
Product     : Fedora 10
Version     : 2.1.1
Release     : 2.fc10
URL         : https://rubyonrails.org/
Summary     : Support and utility classes used by the Rails framework
Description :
Utility library which carries commonly used classes and
goodies from the Rails framework

--------------------------------------------------------------------------------
Update Information:

A vulnerability is found on Ruby on Rails in the escaping code for the form
helpers, which also affects the rpms shipped in Fedora Project. Attackers who
can inject deliberately malformed unicode strings into the form helpers can
defeat the escaping checks and inject arbitrary HTML. This issue has been tagged
as CVE-2009-3009.    These new rpms will fix this issue.
--------------------------------------------------------------------------------
ChangeLog:

* Mon Sep 21 2009 Mamoru Tasaka  - 2.1.1-2
- Patch for CVE-2009-3009 (bug 520843)
--------------------------------------------------------------------------------
References:

  [ 1 ] Bug #520843 - CVE-2009-3009 ruby-activesupport: XSS vulnerability
        https://bugzilla.redhat.com/show_bug.cgi?id=520843
--------------------------------------------------------------------------------

This update can be installed with the "yum" update program.  Use 
su -c 'yum update rubygem-activesupport' at the command line.
For more information, refer to "Managing Software with yum",
available at .

All packages are signed with the Fedora Project GPG key.  More details on the
GPG keys used by the Fedora Project can be found at
https://fedoraproject.org/security/
--------------------------------------------------------------------------------

_______________________________________________
Fedora-package-announce mailing list
Fedora-package-announce@redhat.com
http://www.redhat.com/mailman/listinfo/fedora-package-announce

Fedora 10 Update: rubygem-activesupport-2.1.1-2.fc10

September 24, 2009
A vulnerability is found on Ruby on Rails in the escaping code for the form helpers, which also affects the rpms shipped in Fedora Project

Summary

Utility library which carries commonly used classes and

goodies from the Rails framework

Update Information:

A vulnerability is found on Ruby on Rails in the escaping code for the form helpers, which also affects the rpms shipped in Fedora Project. Attackers who can inject deliberately malformed unicode strings into the form helpers can defeat the escaping checks and inject arbitrary HTML. This issue has been tagged as CVE-2009-3009. These new rpms will fix this issue.

Change Log

* Mon Sep 21 2009 Mamoru Tasaka - 2.1.1-2 - Patch for CVE-2009-3009 (bug 520843)

References

[ 1 ] Bug #520843 - CVE-2009-3009 ruby-activesupport: XSS vulnerability https://bugzilla.redhat.com/show_bug.cgi?id=520843

Update Instructions

This update can be installed with the "yum" update program. Use su -c 'yum update rubygem-activesupport' at the command line. For more information, refer to "Managing Software with yum", available at .

Severity
Name : rubygem-activesupport
Product : Fedora 10
Version : 2.1.1
Release : 2.fc10
URL : https://rubyonrails.org/
Summary : Support and utility classes used by the Rails framework

Related News