oval:org.mitre.oval:def:12767

Definition Id: oval:org.mitre.oval:def:12767
 
Oval ID: oval:org.mitre.oval:def:12767
Title: DSA-2260-1 rails -- several
Description: Two vulnerabilities were discovered in Ruby on Rails, a web application framework. The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2009-3086 The cookie store may be vulnerability to a timing attack, potentially allowing remote attackers to forge message digests. CVE-2009-4214 A cross-site scripting vulnerability in the strip_tags function allows remote user-assisted attackers to inject arbitrary web script.
Family: unix Class: patch
Reference(s): DSA-2260-1
CVE-2009-3086
CVE-2009-4214
Version: 5
Platform(s): Debian GNU/Linux 5.0
Product(s): rails
Definition Synopsis:
Definition Id: oval:org.mitre.oval:def:6513
 
Oval ID: oval:org.mitre.oval:def:6513
Title: Debian GNU/Linux 5.0 is installed
Description: Debian GNU/Linux 5.0 (lenny) is installed
Family: unix Class: inventory
Reference(s): cpe:/o:debian:debian_gnu/linux:5.0
Version: 7
Platform(s): Debian GNU/Linux 5.0
Product(s):
Definition Synopsis:
Referenced By:
oval:org.mitre.oval:def:12767