FYI…

Ruby update - SSL vuln
- https://isc.sans.edu/diary.html?storyid=16076
Last Updated: 2013-06-27 16:57:11 UTC - "An update has been released for the SSL vulnerability reported in Ruby. From the site: "All Ruby versions are affected". The Ruby update also contains a patch for a DOS vulnerability… details here*."
* http://h-online.com/-1901986
___

- http://www.securitytracker.com/id/1028714
CVE Reference: CVE-2013-4073
Jun 27 2013
Impact: Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information
Fix Available: Yes Vendor Confirmed: Yes
Version(s): prior to versions 1.8.7-p374, 1.9.3-p448, 2.0.0-p247
Impact: A remote user can spoof SSL servers in certain cases.
Solution: The vendor has issued a fix (1.8.7-p374, 1.9.3-p448, 2.0.0-p247).
… vendor's advisory is available at:
- http://www.ruby-lang.org/en/news/2013/06/2…-cve-2013-4073/

- https://secunia.com/advisories/54011/
Release Date: 2013-06-28
Where: From remote
Impact: Spoofing
Solution Status: Vendor Patch
CVE Reference: CVE-2013-4073
Solution: Update to version Ruby 1.8.7-p374, 1.9.3-p448, or 2.0.0-p247.
Original Advisory: Ruby:
http://www.ruby-lang.org/en/news/2013/06/2…-cve-2013-4073/
___

Ruby 1.8.7 retired
- http://www.ruby-lang.org/en/news/2013/06/30/we-retire-1-8-7/
30 Jun 2013

:ph34r: :ph34r: