<?xml version="1.0" encoding="UTF-8"?>
<!--PATCHINFO id="c147c81633c8cf23c7022e50919e2209"!-->
<update status="stable" from="maint-coord@suse.de" type="security" version="1070">
  <id>dbg111-ruby</id>
  <title>ruby: update for several security issues</title>
  <release>openSUSE 11.1</release>
  <issued date="1246628178"/>
  <references>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=499253" id="499253" title="bug number 499253" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=478019" id="478019" title="bug number 478019" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=423234" id="423234" title="bug number 423234" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=420084" id="420084" title="bug number 420084" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=415678" id="415678" title="bug number 415678" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=511568" id="511568" title="bug number 511568" type="bugzilla"/>
    <reference href="https://bugzilla.novell.com/show_bug.cgi?id=509914" id="509914" title="bug number 509914" type="bugzilla"/>
  </references>
  <description>This ruby update improves return value checks for openssl
function OCSP_basic_verify() (CVE-2009-0642) which allowed
an attacker to use revoked certificates. The entropy of DNS
identifiers was increased (CVE-2008-3905) to avaid spoofing
attacks. The code for parsing XML data was vulnerable to a
denial of service bug (CVE-2008-3790). An attack on
algorithm complexity was possible in function
WEBrick::HTTP::DefaultFileHandler() while parsing HTTP
requests (CVE-2008-3656) as well as by using the regex
engine (CVE-2008-3443) causing high CPU load. Ruby's access
restriction code (CVE-2008-3655) as well as safe-level
handling using function DL.dlopen() (CVE-2008-3657) and big
decimal handling (CVE-2009-1904) was improved. Bypassing
HTTP basic authentication (authenticate_with_http_digest)
is not possible anymore.
</description>
  <pkglist>
    <collection>
        <package name="ruby-debuginfo" arch="i586" version="1.8.7.p72" release="5.4.1">
          <filename>ruby-debuginfo-1.8.7.p72-5.4.1.i586.rpm</filename>
        </package>
        <package name="ruby-debuginfo" arch="ppc" version="1.8.7.p72" release="5.4.1">
          <filename>ruby-debuginfo-1.8.7.p72-5.4.1.ppc.rpm</filename>
        </package>
        <package name="ruby-debuginfo" arch="x86_64" version="1.8.7.p72" release="5.4.1">
          <filename>ruby-debuginfo-1.8.7.p72-5.4.1.x86_64.rpm</filename>
        </package>
        <package name="ruby-debugsource" arch="i586" version="1.8.7.p72" release="5.4.1">
          <filename>ruby-debugsource-1.8.7.p72-5.4.1.i586.rpm</filename>
        </package>
        <package name="ruby-debugsource" arch="ppc" version="1.8.7.p72" release="5.4.1">
          <filename>ruby-debugsource-1.8.7.p72-5.4.1.ppc.rpm</filename>
        </package>
        <package name="ruby-debugsource" arch="x86_64" version="1.8.7.p72" release="5.4.1">
          <filename>ruby-debugsource-1.8.7.p72-5.4.1.x86_64.rpm</filename>
        </package>
    </collection>
  </pkglist>
</update>
