USN-146-1: Ruby vulnerability
29 June 2005
Ruby vulnerability
Releases
Details
Nobuhiro IMAI discovered that the changed default value of the
Module#public_instance_methods() method broke the security protection
of XMLRPC server handlers. A remote attacker could exploit this to
execute arbitrary commands on an XMLRPC server.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 5.04
-
libxmlrpc-ruby1.8
-
-
ruby1.8
-
Ubuntu 4.10
-
libxmlrpc-ruby1.8
-
-
ruby1.8
-
In general, a standard system update will make all the necessary changes.