RHSA-2013:1441: Moderate: rubygems security update
RubyGems is the Ruby standard for publishing and managing third-partylibraries.It was found that RubyGems did not verify SSL connections. This could leadto man-in-the-middle attacks. (CVE-2012-2126)It was found that, when using RubyGems, the connection could be redirectedfrom HTTPS to HTTP. This could lead to a user believing they are installinga gem via HTTPS, when the connection may have been silently downgraded toHTTP. (CVE-2012-2125)It was discovered that the rubygems API validated version strings using anunsafe regular expression. An application making use of this API to processa version string from an untrusted source could be vulnerable to a denialof service attack through CPU exhaustion. (CVE-2013-4287)Red Hat would like to thank Rubygems upstream for reporting CVE-2013-4287.Upstream acknowledges Damir Sharipov as the original reporter.All rubygems users are advised to upgrade to this updated package, whichcontains backported patches to correct these issues.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of RHSA-2013:1441?
The severity of RHSA-2013:1441 is classified as moderate.
What vulnerabilities are addressed by RHSA-2013:1441?
RHSA-2013:1441 addresses vulnerabilities related to the lack of SSL verification in RubyGems, which could lead to man-in-the-middle attacks.
How do I fix RHSA-2013:1441?
To fix RHSA-2013:1441, upgrade RubyGems to version 1.3.7-4.el6_4 or a later version.
What are the affected versions for RHSA-2013:1441?
The affected versions for RHSA-2013:1441 include RubyGems versions prior to 1.3.7-4.el6_4.
Is RHSA-2013:1441 related to any specific CVEs?
Yes, RHSA-2013:1441 is related to CVE-2012-2126, which involves SSL verification issues.