English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

Debian update for rails


Secunia ID

SA49046

CVE-ID

CVE-2012-1099

Release Date

10 May 2012

Criticality

Less Critical

Solution Status

Vendor Patch

Where

From remote

Impact
Cross-Site Scripting

Cross-Site Scripting vulnerabilities allow a third party to manipulate the content or behaviour of a web application in a user's browser, without compromising the underlying system.

Different Cross-Site Scripting related vulnerabilities are also classified under this category, including "script insertion" and "cross-site request forgery".

Cross-Site Scripting vulnerabilities are often used against specific users of a website to steal their credentials or to conduct spoofing attacks.

Description

Debian has issued an update for rails. This fixes a vulnerability, which can be exploited by malicious people to conduct cross-site scripting attacks.

For more information see vulnerability #2 in:
SA48241

Solution

Apply updated packages via the apt-get package manager.

Original Advisory

DSA-2466-1:
http://www.debian.org/security/2012/dsa-2466