Security update for the Ruby on Rails stack

Announcement ID: SUSE-SU-2017:2716-1
Rating: moderate
References:
Cross-References:
CVSS scores:
  • CVE-2016-2098 ( NVD ): 7.3 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
  • CVE-2016-6316 ( NVD ): 6.1 CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
  • CVE-2016-6317 ( NVD ): 7.5 CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Affected Products:
  • SUSE Enterprise Storage 3
  • SUSE Enterprise Storage 4
  • SUSE Linux Enterprise High Performance Computing 12 SP2
  • SUSE Linux Enterprise Server 12 SP1
  • SUSE Linux Enterprise Server 12 SP2
  • SUSE Linux Enterprise Server for SAP Applications 12 SP1
  • SUSE Linux Enterprise Server for SAP Applications 12 SP2
  • SUSE OpenStack Cloud 6
  • SUSE OpenStack Cloud 7

An update that solves three vulnerabilities and has one security fix can now be installed.

Description:

This update brings version 4.2.9 of the Ruby on Rails stack to provide the latest fixes and improvements from upstream.

The following security issues have been fixed by upstream:

rubygem-actionpack-4_2

  • CVE-2016-2098: Action Pack in Ruby on Rails allowed remote attackers to execute arbitrary Ruby code by leveraging an application's unrestricted use of the render method (bsc#968849).

rubygem-activerecord-4_2

  • CVE-2016-6317: Action Record did not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allowed remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request (bsc#993313).

rubygem-actionview-4_2

  • CVE-2016-6316: Cross-site scripting (XSS) vulnerability in Action View might have allowed remote attackers to inject arbitrary web script or HTML via text declared as "HTML safe" and used as attribute values in tag handlers (bsc#993302).

Additionally, the following packages have been updated to version 4.2.9:

  • rubygem-rails-4_2
  • rubygem-railties-4_2
  • rubygem-activesupport-4_2
  • rubygem-activerecord-4_2
  • rubygem-activejob-4_2
  • rubygem-actionview-4_2
  • rubygem-actionpack-4_2
  • rubygem-actionmailer-4_2

Patch Instructions:

To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:

  • SUSE OpenStack Cloud 6
    zypper in -t patch SUSE-OpenStack-Cloud-6-2017-1679=1
  • SUSE OpenStack Cloud 7
    zypper in -t patch SUSE-OpenStack-Cloud-7-2017-1679=1
  • SUSE Enterprise Storage 3
    zypper in -t patch SUSE-Storage-3-2017-1679=1
  • SUSE Enterprise Storage 4
    zypper in -t patch SUSE-Storage-4-2017-1679=1

Package List:

  • SUSE OpenStack Cloud 6 (x86_64)
    • ruby2.1-rubygem-activerecord-4_2-4.2.9-6.3.1
    • ruby2.1-rubygem-activejob-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionview-4_2-4.2.9-9.3.1
    • ruby2.1-rubygem-activesupport-4_2-4.2.9-7.3.1
    • ruby2.1-rubygem-railties-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionmailer-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionpack-4_2-4.2.9-7.3.1
    • ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.3.1
    • ruby2.1-rubygem-rails-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-activemodel-4_2-4.2.9-6.3.1
  • SUSE OpenStack Cloud 7 (x86_64)
    • ruby2.1-rubygem-activerecord-4_2-4.2.9-6.3.1
    • ruby2.1-rubygem-activejob-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionview-4_2-4.2.9-9.3.1
    • ruby2.1-rubygem-activesupport-4_2-4.2.9-7.3.1
    • ruby2.1-rubygem-railties-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionmailer-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionpack-4_2-4.2.9-7.3.1
    • ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.3.1
    • ruby2.1-rubygem-rails-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-activemodel-4_2-4.2.9-6.3.1
  • SUSE Enterprise Storage 3 (x86_64)
    • ruby2.1-rubygem-activerecord-4_2-4.2.9-6.3.1
    • ruby2.1-rubygem-activejob-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionview-4_2-4.2.9-9.3.1
    • ruby2.1-rubygem-activesupport-4_2-4.2.9-7.3.1
    • ruby2.1-rubygem-railties-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionmailer-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionpack-4_2-4.2.9-7.3.1
    • ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.3.1
    • ruby2.1-rubygem-rails-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-activemodel-4_2-4.2.9-6.3.1
  • SUSE Enterprise Storage 4 (aarch64 x86_64)
    • ruby2.1-rubygem-activerecord-4_2-4.2.9-6.3.1
    • ruby2.1-rubygem-activejob-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionview-4_2-4.2.9-9.3.1
    • ruby2.1-rubygem-activesupport-4_2-4.2.9-7.3.1
    • ruby2.1-rubygem-railties-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionmailer-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-actionpack-4_2-4.2.9-7.3.1
    • ruby2.1-rubygem-rails-html-sanitizer-1.0.3-8.3.1
    • ruby2.1-rubygem-rails-4_2-4.2.9-3.3.1
    • ruby2.1-rubygem-activemodel-4_2-4.2.9-6.3.1

References: