CVE-2013-0256
Publication date 6 February 2013
Last updated 24 July 2024
Ubuntu priority
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
Status
Package | Ubuntu Release | Status |
---|---|---|
ruby-defaults | ||
ruby1.8 | ||
ruby1.9 | ||
ruby1.9.1 | ||
Notes
jdstrand
rdoc part of ruby-defaults in Ubuntu 10.04 LTS and lower darkfish.js only present in ruby1.9.1 on Ubuntu 11.10 and later
Patch details
Package | Patch details |
---|---|
ruby1.9.1 |
References
Related Ubuntu Security Notices (USN)
- USN-1733-1
- Ruby vulnerabilities
- 21 February 2013