Fixed vulnerabilities:
- CVE-2014-4975 (VulnLIB link) The encodes() function in pack.c had an off-by-one error that could lead to a stack-based buffer overflow. This could allow remote attackers to cause a denial of service (crash) or arbitrary code execution.
- CVE-2014-8080 (VulnLIB link), CVE-2014-8090 (VulnLIB link) The REXML parser could be coerced into allocating large string objects that could consume all available memory on the system. This could allow remote attackers to cause a denial of service (crash).
Affected distribution:
- Debian 7 / wheezy
- Debian 8 / jessie
Affected Packages:
- ruby1.9.1
Solution:
- Check VulnLIB for fixes for CVEs listed above.
Source:
Tuesday, 10.02.2015