Package : ruby-gnome2
Vulnerability : format string
Problem type : local
Debian-specific: no
CVE Id(s) : CVE-2007-6183
Debian Bug : 453689
It was discovered that ruby-gnome2, GNOME-related bindings for the Ruby
language, didn't properly sanitize input prior to constructing dialogs.
This could allow for the execution of arbitary code if untrusted input
is displayed within a dialog.
For the stable distribution (etch), this problem has been fixed in version
0.15.0-1.1etch1.
For the old stable distribution (sarge), this problem has been fixed in
version 0.12.0-2sarge1.
For the unstable distribution (sid), this problem has been fixed in
version 0.16.0-10.
We recommend that you upgrade your ruby-gnome2 package.
Upgrade instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below: