Release date: 2012-04-20
Updated on: 2012-04-23
Affected Systems:
Rubygems RubyGems 1.9.3
Rubygems RubyGems 0.9.1
Rubygems RubyGems 0.9
Rubygems RubyGems 0.8.11
Unaffected system:
Rubygems RubyGems 1.9.3-p194
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53174
RubyGems is the Ruby standard for releasing and managing third-party libraries.
RubyGems allows spoofing remote libraries through man-in-the-middle attacks when verifying SSL certificates, resulting in spoofing attacks.
<* Source: John Firebaugh
Link: http://secunia.com/advisories/48807/
Http://www.ruby-lang.org/en/news/2012/04/20/ruby-1-9-3-p194-is-released/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Ruby
----
Ruby has released a Security Bulletin (ruby-1-9-3-p194-is-released) and patches for this:
Ruby-1-9-3-p194-is-released: Ruby 1.9.3-p194 is released
Link: http://www.ruby-lang.org/en/news/2012/04/20/ruby-1-9-3-p194-is-released/