shield Security update for rubygem-actionpack-3_2
slewyst13-rubygem-actionpack-3_2-8667


This update fixes the following security issues with rubygem-actionpack: * bnc#853625: i18n missing translation XSS (CVE-2013-4491) * bnc#853627: unsafe query generation risk (incomplete fix for CVE-2013-0155) (CVE-2013-6417) * bnc#853632: number_to_currency XSS (CVE-2013-6415) * bnc#853633: Action View DoS (CVE-2013-6414) * bnc#846239: fix possible DoS vulnerability in the log subscriber component (CVE-2013-4389) Security Issue references: * CVE-2013-4491 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-4491> * CVE-2013-6417 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6417> * CVE-2013-6415 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6415> * CVE-2013-6414 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6414>


cloud_download Downloads

SUSE WebYaST 1.3 unknown
  • Packages
    rubygem-actionpack-3_2
    Web-flow and rendering framework putting the VC in MVC (part of Rails)
    3.2.12-0.11.1 lock rpm
SUSE WebYaST 1.3 unknown
  • Packages
    rubygem-actionpack-3_2
    Web-flow and rendering framework putting the VC in MVC (part of Rails)
    3.2.12-0.11.1 lock rpm
SUSE WebYaST 1.3 unknown
  • Packages
    rubygem-actionpack-3_2
    Web-flow and rendering framework putting the VC in MVC (part of Rails)
    3.2.12-0.11.1 lock rpm
SUSE WebYaST 1.3 unknown
  • Packages
    rubygem-actionpack-3_2
    Web-flow and rendering framework putting the VC in MVC (part of Rails)
    3.2.12-0.11.1 lock rpm
SUSE WebYaST 1.3 unknown
  • Packages
    rubygem-actionpack-3_2
    Web-flow and rendering framework putting the VC in MVC (part of Rails)
    3.2.12-0.11.1 lock rpm