|
|
Log in / Subscribe / Register

Mageia alert MGASA-2018-0449 (ruby-rack)

From:  Mageia Updates <buildsystem-daemon@mageia.org>
To:  updates-announce@ml.mageia.org
Subject:  [updates-announce] MGASA-2018-0449: Updated ruby-rack packages fix security vulnerability
Date:  Thu, 15 Nov 2018 23:05:23 +0100
Message-ID:  <20181115220523.209A69FED9@duvel.mageia.org>

MGASA-2018-0449 - Updated ruby-rack packages fix security vulnerability Publication date: 15 Nov 2018 URL: https://advisories.mageia.org/MGASA-2018-0449.html Type: security Affected Mageia releases: 6 CVE: CVE-2018-16471 Description: There is a possible XSS vulnerability in Rack. Carefully crafted requests can impact the data returned by the `scheme` method on `Rack::Request`.Applications that expect the scheme to be limited to "http" or "https" and do not escape the return value could be vulnerable to an XSS attack (CVE-2018-16471). References: - https://bugs.mageia.org/show_bug.cgi?id=23813 - https://www.openwall.com/lists/oss-security/2018/11/05/2 - https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-1... SRPMS: - 6/core/ruby-rack-1.6.11-1.mga6


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds