UbuntuUpdates.org

Bugs fixes in "ruby1.9.1"

Origin Bug number Title Date fixed
CVE CVE-2012-5371 Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions 2013-02-21
CVE CVE-2013-0269 The JSON gem 1.7.x before 1.7.7, 1.6.x before 1.6.8, and 1.5.x before 1.5.5 allows remote attackers to cause a denial of service (resource consumptio 2013-02-21
CVE CVE-2013-0256 XSS exploit of RDoc documentation generated by rdoc 2013-02-21
CVE CVE-2012-5371 Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions 2013-02-21
CVE CVE-2013-0269 The JSON gem 1.7.x before 1.7.7, 1.6.x before 1.6.8, and 1.5.x before 1.5.5 allows remote attackers to cause a denial of service (resource consumptio 2013-02-21
CVE CVE-2013-0256 XSS exploit of RDoc documentation generated by rdoc 2013-02-21
CVE CVE-2012-5371 Ruby (aka CRuby) 1.9 before 1.9.3-p327 and 2.0 before r37575 computes hash values without properly restricting the ability to trigger hash collisions 2013-02-21
CVE CVE-2012-4522 ruby Unintentional file creation caused by inserting a illegal NUL character 2012-10-23
CVE CVE-2012-4522 ruby Unintentional file creation caused by inserting a illegal NUL character 2012-10-23
CVE CVE-2012-4522 ruby Unintentional file creation caused by inserting a illegal NUL character 2012-10-23
CVE CVE-2012-4522 ruby Unintentional file creation caused by inserting a illegal NUL character 2012-10-23
CVE CVE-2011-1005 The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via 2012-09-26
CVE CVE-2011-1005 The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via 2012-09-26
CVE CVE-2011-1005 The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via 2012-09-26
CVE CVE-2011-1005 The safe-level feature in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, and 1.8.8dev allows context-dependent attackers to modify strings via 2012-09-26
Launchpad 1021604 ruby uses broken internal get/setcontext routines ... 2012-07-16
Launchpad 1021604 ruby uses broken internal get/setcontext routines ... 2012-07-16
Launchpad 1021604 ruby uses broken internal get/setcontext routines ... 2012-07-06
Launchpad 1021604 ruby uses broken internal get/setcontext routines ... 2012-07-06



About   -   Send Feedback to @ubuntu_updates