Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.881804
Kategorie:CentOS Local Security Checks
Titel:CentOS Update for rubygems CESA-2013:1441 centos6
Zusammenfassung:The remote host is missing an update for the 'rubygems'; package(s) announced via the referenced advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'rubygems'
package(s) announced via the referenced advisory.

Vulnerability Insight:
RubyGems is the Ruby standard for publishing and managing third-party
libraries.

It was found that RubyGems did not verify SSL connections. This could lead
to man-in-the-middle attacks. (CVE-2012-2126)

It was found that, when using RubyGems, the connection could be redirected
from HTTPS to HTTP. This could lead to a user believing they are installing
a gem via HTTPS, when the connection may have been silently downgraded to
HTTP. (CVE-2012-2125)

It was discovered that the rubygems API validated version strings using an
unsafe regular expression. An application making use of this API to process
a version string from an untrusted source could be vulnerable to a denial
of service attack through CPU exhaustion. (CVE-2013-4287)

Red Hat would like to thank Rubygems upstream for reporting CVE-2013-4287.
Upstream acknowledges Damir Sharipov as the original reporter.

All rubygems users are advised to upgrade to this updated package, which
contains backported patches to correct these issues.

Affected Software/OS:
rubygems on CentOS 6

Solution:
Please install the updated packages.

CVSS Score:
5.8

CVSS Vector:
AV:N/AC:M/Au:N/C:P/I:P/A:N

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-2125
https://bugzilla.redhat.com/show_bug.cgi?id=814718
http://www.openwall.com/lists/oss-security/2012/04/20/24
RedHat Security Advisories: RHSA-2013:1203
http://rhn.redhat.com/errata/RHSA-2013-1203.html
RedHat Security Advisories: RHSA-2013:1441
http://rhn.redhat.com/errata/RHSA-2013-1441.html
RedHat Security Advisories: RHSA-2013:1852
http://rhn.redhat.com/errata/RHSA-2013-1852.html
http://secunia.com/advisories/55381
http://www.ubuntu.com/usn/USN-1582-1/
Common Vulnerability Exposure (CVE) ID: CVE-2012-2126
Common Vulnerability Exposure (CVE) ID: CVE-2013-4287
http://www.openwall.com/lists/oss-security/2013/09/10/1
RedHat Security Advisories: RHSA-2013:1427
http://rhn.redhat.com/errata/RHSA-2013-1427.html
RedHat Security Advisories: RHSA-2013:1523
http://rhn.redhat.com/errata/RHSA-2013-1523.html
RedHat Security Advisories: RHSA-2014:0207
http://rhn.redhat.com/errata/RHSA-2014-0207.html
CopyrightCopyright (C) 2013 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.