VDB

MAGEIA-2015-74

MAGEIA-2015-74 PUBLISHED

Updated ruby-sprockets packages fix security vulnerabilities: Multiple directory traversal vulnerabilities in server.rb in Sprockets 2.12.x before 2.12.3, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with double slashes or URL encoding (CVE-2014-7819).

Affected Products

VendorProductVersions
Mageiaruby-sprockets0, 0, 2.10.0-4.1.mga4
Mageiaparcellite0, 1.1.9-1.mga5

Timeline

  • Feb 19, 2015 CVE Updated
  • Feb 19, 2015 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›