[ruby-list:49786] Ubuntu 12.04 LTSでのCVE-2014-2525対応方法
From:
Yuumi Yoshida <yuumi3@...>
Date:
2014-04-10 06:05:05 UTC
List:
ruby-list #49786
Yuumi3 =E3=81=A7=E3=81=99=E3=80=82 Ubuntu 12.04 LTS=E4=B8=8A=E3=81=AE Ruby 2.1.1 =E3=81=A7 Rails4.04 = =E3=82=92=E4=BD=BF=E3=81=A3=E3=81=9F=E3=82=A2=E3=83=97=E3=83=AA=E3=82=92=E9= =81=8B=E7=94=A8=E3=81=97=E3=81=A6=E3=81=84=E3=81=BE=E3=81=99=E3=80=82 Ruby 2.1.1 =E3=81=AF=E3=82=BD=E3=83=BC=E3=82=B9=E3=81=8B=E3=82=89 = ./configure; make; make install =E3=81=97=E3=81=A6=E3=81=84=E3=81=BE=E3=81= =99=E3=80=82 CVE-2014-2525 ( = https://www.ruby-lang.org/ja/news/2014/03/29/heap-overflow-in-yaml-uri-esc= ape-parsing-cve-2014-2525/ ) =E5=AF=BE=E5=BF=9C=E6=96=B9=E6=B3=95=E3=81=A7=E3=81=99=E3=81=8C Ubuntu 12.04 LTS =E3=81=A7=E3=81=AF CVE-2014-2525 = =E3=81=AB=E5=AF=BE=E5=BF=9C=E3=81=97=E3=81=9F=E3=82=A2=E3=83=83=E3=83=97=E3= =83=87=E3=83=BC=E3=83=88 USN-2160-1 http://www.ubuntu.com/usn/usn-2160-1/ = =E3=81=8C=E5=87=BA=E3=81=A6=E3=81=84=E3=82=8B=E3=81=AE=E3=81=A7=E3=80=81 $ sudo apt-get update $ sudo apt-get dist-upgrade =E3=81=A7 libyaml (libyaml-dev) =E3=81=8C=E5=AF=BE=E5=BF=9C=E3=81=95=E3=82= =8C=E3=81=BE=E3=81=99=E3=80=82 =E3=81=93=E3=81=AE=E5=BE=8C = Rails=E3=82=92=E5=8B=95=E3=81=8B=E3=81=97=E3=81=A6=E3=81=84=E3=82=8BUnicor= n=E3=82=92=E5=86=8D=E8=B5=B7=E5=8B=95=E3=81=99=E3=82=8C=E3=81=B0=E8=89=AF=E3= =81=84=E3=81=AE=E3=81=A7=E3=81=97=E3=82=87=E3=81=86=E3=81=8B=EF=BC=9F =E3=81=9F=E3=81=A0=E3=81=97=E3=80=81=E3=81=93=E3=81=AE=E6=96=B9=E6=B3=95=E3= =81=A7=E3=82=A2=E3=83=83=E3=83=97=E3=83=87=E3=83=BC=E3=83=88=E3=81=97=E3=81= =9F=E5=A0=B4=E5=90=88=E3=81=AF libyaml = =E3=81=AE=E3=83=90=E3=83=BC=E3=82=B8=E3=83=A7=E3=83=B3=E3=81=AF=E4=B8=8A=E3= =81=8C=E3=82=89=E3=81=AA=E3=81=84=E3=81=AE=E3=81=A7 $ ruby -rpsych -e 'p Psych.libyaml_version=E2=80=99 =E3=81=AE=E7=B5=90=E6=9E= =9C=E3=81=AF [0, 1, 4] =E3=81=A7=E3=81=99=E3=81=97=E3=80=82 rake =E7=AD=89=E3=82=92=E5=AE=9F=E8=A1=8C=E3=81=99=E3=82=8B=E3=81=A8=E3=80= =81 SafeYAML Warning ---------------- You appear to have an outdated version of libyaml (0.1.4) installed on = your system. =E3=81=8C=E8=A1=A8=E7=A4=BA=E3=81=95=E3=82=8C=E3=81=BE=E3=81=99=E3=81=8C=E3= =80=81Ubuntu 12.04 LTS = =E3=81=AE=E3=82=A2=E3=83=83=E3=83=97=E3=83=87=E3=83=BC=E3=83=88=E3=81=8C=E6= =AD=A3=E3=81=97=E3=81=8F=E8=A1=8C=E3=82=8F=E3=82=8C=E3=81=A6=E3=81=84=E3=82= =8C=E3=81=B0 =E5=95=8F=E9=A1=8C=E7=84=A1=E3=81=84=E3=81=A8=E3=81=84=E3=81=86=E3=81=93=E3= =81=A8=E3=81=A7=E8=89=AF=E3=81=84=E3=81=AE=E3=81=A7=E3=81=97=E3=82=87=E3=81= =86=E3=81=8B=EF=BC=9F --=20 =E2=99=AA =E5=90=89=E7=94=B0 =E8=A3=95=E7=BE=8E (Yuumi Yoshida) =E2=99=AA Blog http://d.hatena.ne.jp/yuum3/ =E2=99=AA HomePage http://www.ey-office.com/ =E2=99=AA Twitter yuumi3 --=20 =E2=99=AA =E5=90=89=E7=94=B0 =E8=A3=95=E7=BE=8E (Yuumi Yoshida) =E2=99=AA Blog http://d.hatena.ne.jp/yuum3/ =E2=99=AA HomePage http://www.ey-office.com/ =E2=99=AA Twitter yuumi3