Risks
Advisories
Browse
or
or
SUSE Security Update - rubygem-crack (SUSE-SU-2013:0615-1)
SUSE Security Update: Security update for rubygem-crack
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:0615-1
Rating:             important
References:         #804721
Cross-References:   CVE-2013-0269
Affected Products:
                    SUSE Studio Onsite 1.2
                    SUSE Studio Extension for System z 1.2
______________________________________________________________________________

   An update that fixes one vulnerability is now available.

Description:


   The Ruby Gem crack has been updated to 0.1.7 and to fix a
   security issue:

   * CVE-2013-1800: Multiple xml parsing issues were fixed
   that could be used by attackers able to inject XML to cause
   denial of service problems.

   Security Issue reference:

   * CVE-2013-0269
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0269
   >


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Studio Onsite 1.2:

      zypper in -t patch slestso12-rubygem-crack-7530

   - SUSE Studio Extension for System z 1.2:

      zypper in -t patch slestso12-rubygem-crack-7530

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Studio Onsite 1.2 (x86_64):

      rubygem-crack-0.1.7-0.5.4

   - SUSE Studio Extension for System z 1.2 (s390x):

      rubygem-crack-0.1.7-0.5.4


References:

   http://support.novell.com/security/cve/CVE-2013-0269.html
   https://bugzilla.novell.com/804721
   http://download.novell.com/patch/finder/?keywords=db8654d7f66749acf4c49dd5a2d0d4a5




Spotlight

The evolution of backup and disaster recovery

Posted on 25 July 2014.  |  Amanda Strassle, IT Senior Director of Data Center Service Delivery at Seagate Technology, talks about enterprise backup issues, illustrates how the cloud shaping an IT department's approach to backup and disaster recovery, and more.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  

DON'T
MISS

Mon, Jul 28th
    COPYRIGHT 1998-2014 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //