SuSE: 2013:0647-1: important: Ruby 1.9
Summary
The Ruby script interpreter 1.9 has been updated to 1.9.3
p392 fixing various bugs and security issues:
This release includes security fixes about bundled JSON and
REXML.
* Denial of Service and Unsafe Object Creation
Vulnerability in JSON (CVE-2013-0269)
* Entity expansion DoS vulnerability in REXML (XML bomb)
* XSS exploit of RDoc documentation generated by rdoc
(CVE-2013-0256)
And some small bugfixes are also included see
/usr/share/doc/packages/ruby19/Changelog for more details
Also the following bugfix was added:
* added bind_stack.patch: (bnc#796757) Fixes stack
boundary issues when embedding Ruby into threaded C code
(Ruby bug #229)
Security Issue reference:
* CVE-2013-0269
References
#783511 #789983 #791199 #796757 #802406 #803342
Cross- CVE-2013-0269
Affected Products:
SUSE Studio Onsite 1.3
https://www.suse.com/security/cve/CVE-2013-0269.html
https://bugzilla.novell.com/783511
https://bugzilla.novell.com/789983
https://bugzilla.novell.com/791199
https://bugzilla.novell.com/796757
https://bugzilla.novell.com/802406
https://bugzilla.novell.com/803342
https://login.microfocus.com/nidp/app/login