English
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service. Internet threat level: 1

SUSE update for rubygem-actionpack/activerecord


Secunia ID

SA50160

CVE-ID

CVE-2012-2660, CVE-2012-2694, CVE-2012-2695

Release Date

10 Aug 2012

Criticality

Moderately Critical

Solution Status

Vendor Patch

Where

From remote

Impact
Manipulation of data

This includes vulnerabilities where a user or a remote attacker can manipulate local data on a system, but not necessarily be able to gain escalated privileges or system access.

The most frequent type of vulnerabilities with this impact are SQL-injection vulnerabilities, where a malicious user or person can manipulate SQL queries.

Description

SUSE has issued an update for rubygem-actionpack/activerecord. This fixes two vulnerabilities, which can be exploited by malicious people to conduct SQL injection attacks.

For more information:
SA49297
SA49457

Solution

Apply updated packages via the zypper package manager.

Original Advisory

openSUSE-SU-2012:0978-1:
http://lists.opensuse.org/opensuse-updates/2012-08/msg00020.html