Risks
Advisories
Browse
or
or
SUSE Security Update - rubygem-crack (SUSE-SU-2013:0615-1)
SUSE Security Update: Security update for rubygem-crack
______________________________________________________________________________

Announcement ID:    SUSE-SU-2013:0615-1
Rating:             important
References:         #804721
Cross-References:   CVE-2013-0269
Affected Products:
                    SUSE Studio Onsite 1.2
                    SUSE Studio Extension for System z 1.2
______________________________________________________________________________

   An update that fixes one vulnerability is now available.

Description:


   The Ruby Gem crack has been updated to 0.1.7 and to fix a
   security issue:

   * CVE-2013-1800: Multiple xml parsing issues were fixed
   that could be used by attackers able to inject XML to cause
   denial of service problems.

   Security Issue reference:

   * CVE-2013-0269
   <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0269
   >


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE Studio Onsite 1.2:

      zypper in -t patch slestso12-rubygem-crack-7530

   - SUSE Studio Extension for System z 1.2:

      zypper in -t patch slestso12-rubygem-crack-7530

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE Studio Onsite 1.2 (x86_64):

      rubygem-crack-0.1.7-0.5.4

   - SUSE Studio Extension for System z 1.2 (s390x):

      rubygem-crack-0.1.7-0.5.4


References:

   http://support.novell.com/security/cve/CVE-2013-0269.html
   https://bugzilla.novell.com/804721
   http://download.novell.com/patch/finder/?keywords=db8654d7f66749acf4c49dd5a2d0d4a5




Spotlight

10 practical security tips for DevOps

By working with the DevOps team, you can ensure that the production environment is more predictable, auditable and more secure than before. The key is to integrate your security requirements into the DevOps pipeline.


Weekly newsletter

Reading our newsletter every Monday will keep you up-to-date with security news.
  



Daily digest

Receive a daily digest of the latest security news.
  
DON'T
MISS

Tue, Mar 31st
    COPYRIGHT 1998-2015 BY HELP NET SECURITY.   // READ OUR PRIVACY POLICY // ABOUT US // ADVERTISE //