Advisories ยป MGASA-2014-0003

Updated ruby package fixes security vulnerability

Publication date: 06 Jan 2014
Modification date: 06 Jan 2014
Type: security
Affected Mageia releases : 3
CVE: CVE-2013-4164

Description

Charlie Somerville discovered that Ruby incorrectly handled floating point
number conversion. An attacker could possibly use this issue with an
application that converts text to floating point numbers to cause the
application to crash, resulting in a denial of service, or possibly
execute arbitrary code (CVE-2013-4164).
                

References

SRPMS

3/core