Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4E9D8B1B.90909@redhat.com>
Date: Tue, 18 Oct 2011 08:20:11 -0600
From: Kurt Seifried <kseifried@...hat.com>
To: oss-security@...ts.openwall.com
CC: Matthias Weckbecker <mweckbecker@...e.de>
Subject: Re: Ruby 1.9.2-p290 WEBrick::HTTPRequest X-Forwarded-*

Matthias Weckbecker <mweckbecker@...e.de> wrote:
>> https://redmine.ruby-lang.org/issues/5418
>>
>> Can we get a CVE for this please?
>>
> I think this is already covered by CVE-2011-3187.

Sort of, similar issue (lack of input verification), but it's in a
different code base, which traditionally means a different CVE is
assigned. Also CVE-2011-3187 was fixed in Ruby on Rails 3.0.10, this new
issue is still unfixed in Ruby.
 

-- 

-Kurt Seifried / Red Hat Security Response Team

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.