Advisories Blog | G5 Cyber Security

Gentoo Linux Security Advisory 200608-20

Gentoo Linux Security Advisory GLSA 200608-20 – The Ruby on Rails developers have corrected some weaknesses in action_controller/, relative to the handling of the user input and the LOAD_PATH variable. A remote attacker could inject arbitrary entries into the LOAD_PATH variable and alter the main Ruby on Rails process. The security hole has only been partly solved in version 1.1.5. Version 1.1.6 now fully corrects it. Versions less than 1.1.6 are affected.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/49288/glsa-200608-20.txt

Source: https://packetstormsecurity.com/files/49288/Gentoo-Linux-Security-Advisory-200608-20.html

Exit mobile version