[Secure-testing-team] Bug#690670: ruby1.9.1: CVE-2012-4522

Moritz Muehlenhoff jmm at inutil.org
Tue Oct 16 09:39:01 UTC 2012


Package: ruby1.9.1
Severity: grave
Tags: security
Justification: user security hole

Please see http://www.ruby-lang.org/en/news/2012/10/12/poisoned-NUL-byte-vulnerability/

The advisory doesn't mention Ruby 1.8, can you please double-check, whether it is
affected?

Cheers,
        Moritz



More information about the Secure-testing-team mailing list