Fedora 11 : ruby-1.8.6.383-6.fc11 (2010-0533)

This script is Copyright (C) 2010-2016 Tenable Network Security, Inc.


Synopsis :

The remote Fedora host is missing a security update.

Description :

A secrity vulnerability is found on WEBrick module in Ruby currently
shipped on Fedora 11 that WEBrick lets attackers to inject malicious
escape sequences to its logs, making it possible for dangerous control
characters to be executed on a victim's terminal emulator. This issue
has now been tagged as CVE-2009-4492. Also currently have_library()
function in mkmf.rb always requires ruby's static archive to function
correctly despite that ruby shared library is also provided. This new
rpm will fix these issues.

Note that Tenable Network Security has extracted the preceding
description block directly from the Fedora security advisory. Tenable
has attempted to automatically clean and format it as much as possible
without introducing additional issues.

See also :

https://bugzilla.redhat.com/show_bug.cgi?id=554485
http://www.nessus.org/u?3e06cbe0

Solution :

Update the affected ruby package.

Risk factor :

Medium / CVSS Base Score : 5.0
(CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N)
CVSS Temporal Score : 4.3
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : true

Family: Fedora Local Security Checks

Nessus Plugin ID: 47190 (fedora_2010-0533.nasl)

Bugtraq ID: 35278
37710

CVE ID: CVE-2009-4492

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now