RHSA-2013:0582: Moderate: Red Hat OpenShift Enterprise 1.1.1 update

Published Feb 28, 2013
·
Updated

OpenShift Enterprise is a cloud computing Platform-as-a-Service (PaaS)solution from Red Hat, and is designed for on-premise or private clouddeployments.Installing the updated packages and restarting the OpenShift services arethe only requirements for this update. However, if you are updating yoursystem to Red Hat Enterprise Linux 6.4 while applying OpenShift Enterprise1.1.1 updates, it is recommended that you restart your system.For further information about this release, refer to the OpenShiftEnterprise 1.1.1 Technical Notes, available shortly fromhttps://access.redhat.com/knowledge/docs/ This update also fixes the following security issues:Multiple cross-site scripting (XSS) flaws were found in rubygem-actionpack.A remote attacker could use these flaws to conduct XSS attacks againstusers of an application using rubygem-actionpack. (CVE-2012-3463,CVE-2012-3464, CVE-2012-3465)It was found that certain methods did not sanitize file names beforepassing them to lower layer routines in Ruby. If a Ruby application createdfiles with names based on untrusted input, it could result in the creationof files with different names than expected. (CVE-2012-4522)A denial of service flaw was found in the implementation of associativearrays (hashes) in Ruby. An attacker able to supply a large number ofinputs to a Ruby application (such as HTTP POST request parameters sent toa web application) that are used as keys when inserting data into an arraycould trigger multiple hash function collisions, making array operationstake an excessive amount of CPU time. To mitigate this issue, a new, morecollision resistant algorithm has been used to reduce the chance of anattacker successfully causing intentional collisions. (CVE-2012-5371)Input validation vulnerabilities were discovered in rubygem-activerecord.A remote attacker could possibly use these flaws to perform an SQLinjection attack against an application using rubygem-activerecord.(CVE-2012-2661, CVE-2012-2695, CVE-2013-0155)Input validation vulnerabilities were discovered in rubygem-actionpack. Aremote attacker could possibly use these flaws to perform an SQL injectionattack against an application using rubygem-actionpack andrubygem-activerecord. (CVE-2012-2660, CVE-2012-2694)A flaw was found in the HTTP digest authentication implementation inrubygem-actionpack. A remote attacker could use this flaw to cause adenial of service of an application using rubygem-actionpack and digestauthentication. (CVE-2012-3424)A flaw was found in the handling of strings in Ruby safe level 4. A remoteattacker can use Exception#tos to destructively modify an untainted stringso that it is tainted, the string can then be arbitrarily modified.(CVE-2012-4466)A flaw was found in the method for translating an exception message into astring in the Ruby Exception class. A remote attacker could use this flawto bypass safe level 4 restrictions, allowing untrusted (tainted) code tomodify arbitrary, trusted (untainted) strings, which safe level 4restrictions would otherwise prevent. (CVE-2012-4464)It was found that rubyparser from rubygem-rubyparser created a temporaryfile in an insecure way. A local attacker could use this flaw to perform asymbolic link attack, overwriting arbitrary files accessible to theapplication using rubyparser. (CVE-2013-0162)The CVE-2013-0162 issue was discovered by Michael Scherer of the Red HatRegional IT team.Users are advised to upgrade to Red Hat OpenShift Enterprise 1.1.1.

Affected Software

71 affected componentsFixes available
redhat/graphviz<2.26.0-10.el6
2.26.0-10.el6
redhat/openshift-console<0.0.16-1.el6
0.0.16-1.el6
redhat/openshift-origin-broker<1.0.11-1.el6
1.0.11-1.el6
redhat/openshift-origin-broker-util<1.0.15-1.el6
1.0.15-1.el6
redhat/ruby193-ruby<1.9.3.327-25.el6
1.9.3.327-25.el6
redhat/ruby193-rubygem-actionpack<3.2.8-3.el6
3.2.8-3.el6
redhat/ruby193-rubygem-activemodel<3.2.8-2.el6
3.2.8-2.el6
redhat/ruby193-rubygem-activerecord<3.2.8-3.el6
3.2.8-3.el6
redhat/ruby193-rubygem-railties<3.2.8-2.el6
3.2.8-2.el6
redhat/rubygem-actionpack<3.0.13-4.el6
3.0.13-4.el6
redhat/rubygem-activemodel<3.0.13-3.el6
3.0.13-3.el6
redhat/rubygem-activerecord<3.0.13-5.el6
3.0.13-5.el6
redhat/rubygem-bson<1.8.1-2.el6
1.8.1-2.el6
redhat/rubygem-mongo<1.8.1-2.el6
1.8.1-2.el6
redhat/rubygem-openshift-origin-auth-remote-user<1.0.5-1.el6
1.0.5-1.el6
redhat/rubygem-openshift-origin-console<1.0.10-1.el6
1.0.10-1.el6
redhat/rubygem-openshift-origin-controller<1.0.12-1.el6
1.0.12-1.el6
redhat/graphviz<2.26.0-10.el6
2.26.0-10.el6
redhat/graphviz-debuginfo<2.26.0-10.el6
2.26.0-10.el6
redhat/graphviz-devel<2.26.0-10.el6
2.26.0-10.el6
redhat/graphviz-doc<2.26.0-10.el6
2.26.0-10.el6
redhat/graphviz-gd<2.26.0-10.el6
2.26.0-10.el6
redhat/graphviz-ruby<2.26.0-10.el6
2.26.0-10.el6
redhat/ruby193-ruby<1.9.3.327-25.el6
1.9.3.327-25.el6
redhat/ruby193-ruby-debuginfo<1.9.3.327-25.el6
1.9.3.327-25.el6
redhat/ruby193-ruby-devel<1.9.3.327-25.el6
1.9.3.327-25.el6
redhat/ruby193-ruby-doc<1.9.3.327-25.el6
1.9.3.327-25.el6
redhat/ruby193-ruby-irb<1.9.3.327-25.el6
1.9.3.327-25.el6
redhat/ruby193-ruby-libs<1.9.3.327-25.el6
1.9.3.327-25.el6
redhat/ruby193-ruby-tcltk<1.9.3.327-25.el6
1.9.3.327-25.el6
redhat/ruby193-rubygem-actionpack<3.2.8-3.el6
3.2.8-3.el6
redhat/ruby193-rubygem-actionpack-doc<3.2.8-3.el6
3.2.8-3.el6
redhat/ruby193-rubygem-activemodel<3.2.8-2.el6
3.2.8-2.el6
redhat/ruby193-rubygem-activemodel-doc<3.2.8-2.el6
3.2.8-2.el6
redhat/ruby193-rubygem-activerecord<3.2.8-3.el6
3.2.8-3.el6
redhat/ruby193-rubygem-activerecord-doc<3.2.8-3.el6
3.2.8-3.el6
redhat/ruby193-rubygem-bigdecimal<1.1.0-25.el6
1.1.0-25.el6
redhat/ruby193-rubygem-io-console<0.3-25.el6
0.3-25.el6
redhat/ruby193-rubygem-json<1.5.4-25.el6
1.5.4-25.el6
redhat/ruby193-rubygem-minitest<2.5.1-25.el6
2.5.1-25.el6
redhat/ruby193-rubygem-railties<3.2.8-2.el6
3.2.8-2.el6
redhat/ruby193-rubygem-railties-doc<3.2.8-2.el6
3.2.8-2.el6
redhat/ruby193-rubygem-rake<0.9.2.2-25.el6
0.9.2.2-25.el6
redhat/ruby193-rubygem-rdoc<3.9.4-25.el6
3.9.4-25.el6
redhat/ruby193-rubygems<1.8.23-25.el6
1.8.23-25.el6
redhat/ruby193-rubygems-devel<1.8.23-25.el6
1.8.23-25.el6
redhat/rubygem-activemodel-doc<3.0.13-3.el6
3.0.13-3.el6
redhat/rubygem-mongo-doc<1.8.1-2.el6
1.8.1-2.el6
redhat/rubygem-openshift-origin-console-doc<1.0.10-1.el6
1.0.10-1.el6
redhat/openshift-origin-cartridge-cron<1.4-1.0.3-1.el6
1.4-1.0.3-1.el6
redhat/openshift-origin-cartridge-diy<0.1-1.0.3-1.el6
0.1-1.0.3-1.el6
redhat/openshift-origin-cartridge-haproxy<1.4-1.0.4-1.el6
1.4-1.0.4-1.el6
redhat/openshift-origin-cartridge-jbossews<1.0-1.0.13-1.el6
1.0-1.0.13-1.el6
redhat/openshift-origin-cartridge-jenkins<1.4-1.0.2-1.el6
1.4-1.0.2-1.el6
redhat/openshift-origin-cartridge-jenkins-client<1.4-1.0.2-1.el6
1.4-1.0.2-1.el6
redhat/openshift-origin-cartridge-mysql<5.1-1.0.5-1.el6
5.1-1.0.5-1.el6
redhat/openshift-origin-cartridge-perl<5.10-1.0.3-1.el6
5.10-1.0.3-1.el6
redhat/openshift-origin-cartridge-php<5.3-1.0.5-1.el6
5.3-1.0.5-1.el6
redhat/openshift-origin-cartridge-postgresql<8.4-1.0.3-2.el6
8.4-1.0.3-2.el6
redhat/openshift-origin-cartridge-ruby<1.8-1.0.7-1.el6
1.8-1.0.7-1.el6
redhat/openshift-origin-cartridge-ruby<1.9-scl-1.0.8-1.el6
1.9-scl-1.0.8-1.el6
redhat/openshift-origin-msg-node-mcollective<1.0.3-1.el6
1.0.3-1.el6
redhat/php<5.3.3-22.el6
5.3.3-22.el6
redhat/rubygem-openshift-origin-node<1.0.11-1.el6
1.0.11-1.el6
redhat/php-bcmath<5.3.3-22.el6
5.3.3-22.el6
redhat/php-debuginfo<5.3.3-22.el6
5.3.3-22.el6
redhat/php-devel<5.3.3-22.el6
5.3.3-22.el6
redhat/php-imap<5.3.3-22.el6
5.3.3-22.el6
redhat/php-mbstring<5.3.3-22.el6
5.3.3-22.el6
redhat/php-process<5.3.3-22.el6
5.3.3-22.el6
redhat/openshift-origin-cartridge-jbosseap<6.0-1.0.4-1.el6
6.0-1.0.4-1.el6

Remediation

Event History

Feb 28, 2013
Advisory Published
12:00 AM

Frequently Asked Questions

1

What is the severity of RHSA-2013:0582?

The severity of RHSA-2013:0582 is classified as important, indicating potential risk to the application.

2

How do I fix RHSA-2013:0582?

To fix RHSA-2013:0582, install the updated packages and restart the OpenShift services.

3

What packages are affected by RHSA-2013:0582?

RHSA-2013:0582 affects packages such as graphviz, openshift-console, and various ruby and openshift-origin components.

4

When was RHSA-2013:0582 announced?

RHSA-2013:0582 was announced on July 17, 2013.

5

What is OpenShift Enterprise in relation to RHSA-2013:0582?

OpenShift Enterprise is a cloud computing Platform-as-a-Service solution from Red Hat that is addressed in RHSA-2013:0582.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203