Vulnerability Scanning Solutions, LLC.
Home
Our Process
Residential
Corporate
What We Scan For
Sample Report
Client List
Terms
Contact Us
What We Scan For
Family: Ubuntu Local Security Checks --> Category: infos

USN146-1 : ruby1.8 vulnerability Vulnerability Scan


Vulnerability Scan Summary
ruby1.8 vulnerability

Detailed Explanation for this Vulnerability Test

Synopsis :

These remote packages are missing security patches :
- irb1.8
- libbigdecimal-ruby1.8
- libcurses-ruby1.8
- libdbm-ruby1.8
- libdl-ruby1.8
- libdrb-ruby1.8
- liberb-ruby1.8
- libgdbm-ruby1.8
- libiconv-ruby1.8
- libopenssl-ruby1.8
- libpty-ruby1.8
- libracc-runtime-ruby1.8
- libreadline-ruby1.8
- librexml-ruby1.8
- libruby1.8
- libruby1.8-dbg
- libsdbm-ruby1.8
- libsoap-ruby1.8
- libstrscan-ruby1.8
- libsyslog-ruby1.8
- libtcltk-ruby1.8
- libtest-unit-ruby1.8
- libtk-ruby1.8
- libweb
[...]

Description :

Nobuhiro IMAI discovered that the changed default value of the
Module#public_instance_methods() method broke the security protection
of XMLRPC server handlers. A remote attacker could exploit this to
execute arbitrary commands on an XMLRPC server.

Solution :

Upgrade to :
- irb1.8-1.8.1+1.8.2pre4-1ubuntu0.1 (Ubuntu 5.04)
- libbigdecimal-ruby1.8-1.8.1+1.8.2pre4-1ubuntu0.1 (Ubuntu 5.04)
- libcurses-ruby1.8-1.8.1+1.8.2pre4-1ubuntu0.1 (Ubuntu 5.04)
- libdbm-ruby1.8-1.8.1+1.8.2pre4-1ubuntu0.1 (Ubuntu 5.04)
- libdl-ruby1.8-1.8.1+1.8.2pre4-1ubuntu0.1 (Ubuntu 5.04)
- libdrb-ruby1.8-1.8.1+1.8.2pre4-1ubuntu0.1 (Ubuntu 5.04)
- liberb-ruby1.8-1.8.1+1.8.2pre4-1ubuntu0.1 (Ubuntu 5.04)
- libgdbm-ruby1.8-1.8.1+1.8.2pre4-1ubuntu0.1 (Ubuntu 5.04)
- libiconv-ruby1.8-1.8.1+1.8.2p
[...]


Threat Level: High


Click HERE for more information and discussions on this network vulnerability scan.

VSS, LLC.

P.O. Box 827051

Pembroke Pines, FL 33082-7051

Vulnerability Scanning Solutions, LLC.