Gentoo Security Advisory GLSA 201001-09 (ruby)

Summary
The remote host is missing updates announced in advisory GLSA 201001-09.
Solution
All Ruby 1.8.7 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=dev-lang/ruby-1.8.7_p249' All Ruby 1.8.6 users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose '>=dev-lang/ruby-1.8.6_p388' http://www.securityspace.com/smysecure/catid.html?in=GLSA%20201001-09 http://bugs.gentoo.org/show_bug.cgi?id=300468
Insight
An input sanitation flaw in the WEBrick HTTP server included in Ruby might allow remote attackers to inject arbitrary control characters into terminal sessions.