RHSA-2008:0981: Moderate: ruby security update
Ruby is an extensible, interpreted, object-oriented, scripting language. Ithas features to process text files and to do system management tasks.Vincent Danen reported, that Red Hat Security Advisory RHSA-2008:0897did not properly address a denial of service flaw in the WEBrick (RubyHTTP server toolkit), known as CVE-2008-3656. This flaw allowed aremote attacker to send a specially-crafted HTTP request to a WEBrickserver that would cause the server to use excessive CPU time. Thisupdate properly addresses this flaw. (CVE-2008-4310)All Ruby users should upgrade to these updated packages, which contain acorrect patch that resolves this issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2008:0981?
The severity of RHSA-2008:0981 is classified as moderate.
How do I fix RHSA-2008:0981?
To fix RHSA-2008:0981, update the affected packages to the versions specified in the advisory.
Which packages are affected by RHSA-2008:0981?
RHSA-2008:0981 affects various packages including ruby, ruby-devel, and ruby-libs among others.
What kind of issue does RHSA-2008:0981 address?
RHSA-2008:0981 addresses a denial of service vulnerability in Ruby.
Is RHSA-2008:0981 applicable to different architectures?
Yes, RHSA-2008:0981 is applicable to both x86_64 and i386 architectures.