VDB
MAGEIA-2015-74
MAGEIA-2015-74
PUBLISHED
Updated ruby-sprockets packages fix security vulnerabilities: Multiple directory traversal vulnerabilities in server.rb in Sprockets 2.12.x before 2.12.3, allow remote attackers to determine the existence of files outside the application root via a ../ (dot dot slash) sequence with double slashes or URL encoding (CVE-2014-7819).
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mageia | ruby-sprockets | 0, 0, 2.10.0-4.1.mga4 |
| Mageia | parcellite | 0, 1.1.9-1.mga5 |
Timeline
- Feb 19, 2015 CVE Updated
- Feb 19, 2015 CVE Published
References
- Updated ruby-sprockets packages fix CVE-2014-7819 advisory
- Updated ruby-sprockets packages fix CVE-2014-7819 issue
- Updated ruby-sprockets packages fix CVE-2014-7819 issue
- Updated parcellite package fixes entry selection and translations advisory
- Updated parcellite package fixes entry selection and translations issue