From cb406f1256ae46fe9ab2f73d040fad6aaccb1dd4 Mon Sep 17 00:00:00 2001 From: delphij Date: Fri, 19 Aug 2011 18:42:12 +0000 Subject: Document Rails multiple vulnerabilities. --- security/vuxml/vuln.xml | 33 +++++++++++++++++++++++++++++++++ 1 file changed, 33 insertions(+) (limited to 'security') diff --git a/security/vuxml/vuln.xml b/security/vuxml/vuln.xml index d3b658726e69..9d5f38ffff69 100644 --- a/security/vuxml/vuln.xml +++ b/security/vuxml/vuln.xml @@ -34,6 +34,39 @@ Note: Please add new entries to the beginning of this file. --> + + rubygem-rails -- multiple vulnerabilities + + + rubygem-rails + 3.0.10 + + + + +

SecurityFocus reports:

+
+

Ruby on Rails is prone to multiple vulnerabilities + including SQL-injection, information-disclosure, + HTTP-header-injection, security-bypass and cross-site + scripting issues.

+
+ +
+ + 49179 + http://groups.google.com/group/rubyonrails-security/browse_thread/thread/6a1e473744bc389b + http://groups.google.com/group/rubyonrails-security/browse_thread/thread/3420ac71aed312d6 + http://groups.google.com/group/rubyonrails-security/browse_thread/thread/6ffc93bde0298768 + http://groups.google.com/group/rubyonrails-security/browse_thread/thread/2b9130749b74ea12 + http://groups.google.com/group/rubyonrails-security/browse_thread/thread/56bffb5923ab1195 + + + 2011-08-16 + 2011-08-19 + +
+ dovecot -- denial of service vulnerability -- cgit