SUSE-SU-2017:2716-1: moderate: Security update for the Ruby on Rails stack

sle-updates at lists.suse.com sle-updates at lists.suse.com
Thu Oct 12 10:11:21 MDT 2017


   SUSE Security Update: Security update for the Ruby on Rails stack
______________________________________________________________________________

Announcement ID:    SUSE-SU-2017:2716-1
Rating:             moderate
References:         #1055962 #968849 #993302 #993313 
Cross-References:   CVE-2016-2098 CVE-2016-6316 CVE-2016-6317
                   
Affected Products:
                    SUSE OpenStack Cloud 7
                    SUSE OpenStack Cloud 6
                    SUSE Enterprise Storage 4
                    SUSE Enterprise Storage 3
______________________________________________________________________________

   An update that solves three vulnerabilities and has one
   errata is now available.

Description:

   This update brings version 4.2.9 of the Ruby on Rails stack to provide the
   latest fixes and improvements from upstream.

   The following security issues have been fixed by upstream:

   rubygem-actionpack-4_2

   - CVE-2016-2098: Action Pack in Ruby on Rails allowed remote attackers to
     execute arbitrary Ruby code by leveraging an application's unrestricted
     use of the render method (bsc#968849).

   rubygem-activerecord-4_2

   - CVE-2016-6317: Action Record did not properly consider differences in
     parameter handling between the Active Record component and the JSON
     implementation, which allowed remote attackers to bypass intended
     database-query restrictions and perform NULL checks or trigger missing
     WHERE clauses via a crafted request (bsc#993313).

   rubygem-actionview-4_2

   - CVE-2016-6316: Cross-site scripting (XSS) vulnerability in Action View
     might have allowed remote attackers to inject arbitrary web script or
     HTML via text declared as "HTML safe" and used as attribute values in
     tag handlers (bsc#993302).

   Additionally, the following packages have been updated to version 4.2.9:

   - rubygem-rails-4_2
   - rubygem-railties-4_2
   - rubygem-activesupport-4_2
   - rubygem-activerecord-4_2
   - rubygem-activejob-4_2
   - rubygem-actionview-4_2
   - rubygem-actionpack-4_2
   - rubygem-actionmailer-4_2


Patch Instructions:

   To install this SUSE Security Update use YaST online_update.
   Alternatively you can run the command listed for your product:

   - SUSE OpenStack Cloud 7:

      zypper in -t patch SUSE-OpenStack-Cloud-7-2017-1679=1

   - SUSE OpenStack Cloud 6:

      zypper in -t patch SUSE-OpenStack-Cloud-6-2017-1679=1

   - SUSE Enterprise Storage 4:

      zypper in -t patch SUSE-Storage-4-2017-1679=1

   - SUSE Enterprise Storage 3:

      zypper in -t patch SUSE-Storage-3-2017-1679=1

   To bring your system up-to-date, use "zypper patch".


Package List:

   - SUSE OpenStack Cloud 7 (aarch64 s390x x86_64):

      ruby2.1-rubygem-actionmailer-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-actionpack-4_2-4.2.9-7.3.1
      ruby2.1-rubygem-actionview-4_2-4.2.9-9.3.1
      ruby2.1-rubygem-activejob-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-activemodel-4_2-4.2.9-6.3.1
      ruby2.1-rubygem-activerecord-4_2-4.2.9-6.3.1
      ruby2.1-rubygem-activesupport-4_2-4.2.9-7.3.1
      ruby2.1-rubygem-rails-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.3.1
      ruby2.1-rubygem-railties-4_2-4.2.9-3.3.1

   - SUSE OpenStack Cloud 6 (x86_64):

      ruby2.1-rubygem-actionmailer-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-actionpack-4_2-4.2.9-7.3.1
      ruby2.1-rubygem-actionview-4_2-4.2.9-9.3.1
      ruby2.1-rubygem-activejob-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-activemodel-4_2-4.2.9-6.3.1
      ruby2.1-rubygem-activerecord-4_2-4.2.9-6.3.1
      ruby2.1-rubygem-activesupport-4_2-4.2.9-7.3.1
      ruby2.1-rubygem-rails-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.3.1
      ruby2.1-rubygem-railties-4_2-4.2.9-3.3.1

   - SUSE Enterprise Storage 4 (aarch64 x86_64):

      ruby2.1-rubygem-actionmailer-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-actionpack-4_2-4.2.9-7.3.1
      ruby2.1-rubygem-actionview-4_2-4.2.9-9.3.1
      ruby2.1-rubygem-activejob-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-activemodel-4_2-4.2.9-6.3.1
      ruby2.1-rubygem-activerecord-4_2-4.2.9-6.3.1
      ruby2.1-rubygem-activesupport-4_2-4.2.9-7.3.1
      ruby2.1-rubygem-rails-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.3.1
      ruby2.1-rubygem-railties-4_2-4.2.9-3.3.1

   - SUSE Enterprise Storage 3 (aarch64 x86_64):

      ruby2.1-rubygem-actionmailer-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-actionpack-4_2-4.2.9-7.3.1
      ruby2.1-rubygem-actionview-4_2-4.2.9-9.3.1
      ruby2.1-rubygem-activejob-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-activemodel-4_2-4.2.9-6.3.1
      ruby2.1-rubygem-activerecord-4_2-4.2.9-6.3.1
      ruby2.1-rubygem-activesupport-4_2-4.2.9-7.3.1
      ruby2.1-rubygem-rails-4_2-4.2.9-3.3.1
      ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.3.1
      ruby2.1-rubygem-railties-4_2-4.2.9-3.3.1


References:

   https://www.suse.com/security/cve/CVE-2016-2098.html
   https://www.suse.com/security/cve/CVE-2016-6316.html
   https://www.suse.com/security/cve/CVE-2016-6317.html
   https://bugzilla.suse.com/1055962
   https://bugzilla.suse.com/968849
   https://bugzilla.suse.com/993302
   https://bugzilla.suse.com/993313



More information about the sle-updates mailing list