|
|
Log in / Subscribe / Register

Debian-LTS alert DLA-215-1 (libjson-ruby)

From:  Raphael Hertzog <hertzog@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 215-1] libjson-ruby security update
Date:  Thu, 30 Apr 2015 18:34:41 +0200
Message-ID:  <20150430163441.GA1534@home.ouaza.com>

Package : libjson-ruby Version : 1.1.9-1+deb6u1 CVE ID : CVE-2013-0269 The JSON gem for Ruby allowed remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability." For Debian 6 “Squeeze”, this issue has been fixed in libjson-ruby version 1.1.9-1+deb6u1. -- Raphaël Hertzog ◈ Debian Developer Support Debian LTS: http://www.freexian.com/services/debian-lts.html Learn to master Debian: http://debian-handbook.info/get/


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds