Crack: Arbitrary code execution A vulnerability in Crack might allow remote attackers to execute arbitrary code. crack 2014-04-07 2014-04-07 460164 remote 0.3.2 0.3.2

Crack is a really simple JSON and XML parsing Ruby gem, ripped from Merb and Rails.

An XML parameter parsing vulnerability has been discovered in Crack.

A remote attacker could execute arbitrary code with the privileges of the process, cause a Denial of Service condition, or bypass security restrictions.

There is no known workaround at this time.

All Crack users should upgrade to the latest version:

# emerge --sync # emerge --ask --oneshot --verbose ">=dev-ruby/crack-0.3.2"
CVE-2013-1800 ackle ackle