<?xml version="1.0" encoding="utf-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Red Hat Security Advisory: CloudForms Commons 1.1 security update</DocumentTitle>
  <DocumentType>Security Advisory</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>secalert@redhat.com</ContactDetails>
    <IssuingAuthority>Red Hat Security Response Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification><ID>RHSA-2012:1542</ID></Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
       <Revision>
         <Number>1</Number>
         <Date>2012-12-04T19:21:00Z</Date>
         <Description>Current version</Description>
       </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2012-12-04T19:21:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2012-12-04T19:21:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>Red Hat rhsa-to-cvrf 1.0.1484</Engine>
      <Date>2012-12-04T19:31:01Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">
Updated CloudForms Commons packages that fix several security issues are
now available.

The Red Hat Security Response Team has rated this update as having moderate
security impact. Common Vulnerability Scoring System (CVSS) base scores,
which give detailed severity ratings, are available for each vulnerability
from the CVE links in the References section.    </Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
Red Hat CloudForms is an on-premise hybrid cloud
Infrastructure-as-a-Service (IaaS) product that lets you create and manage
private and public clouds.

Multiple input validation vulnerabilities were discovered in
rubygem-activerecored. A remote attacker could possibly use these flaws
to perform an SQL injection attack against an application using
rubygem-activerecord. (CVE-2012-2660, CVE-2012-2661, CVE-2012-2694,
CVE-2012-2695)

Multiple cross-site scripting (XSS) flaws were found in rubygem-actionpack.
A remote attacker could use these flaws to conduct XSS attacks against
users of an application using rubygem-actionpack. (CVE-2012-3463,
CVE-2012-3464, CVE-2012-3465)

A flaw was found in the HTTP digest authentication implementation in
rubygem-actionpack. A remote attacker could use this flaw to cause a
denial of service of an application using rubygem-actionpack and digest
authentication. (CVE-2012-3424)

An input validation flaw was found in rubygem-mail's Exim and Sendmail
delivery methods. A remote attacker could use this flaw to execute
arbitrary commands with the privileges of an application using
rubygem-mail. (CVE-2012-2140)

A directory traversal flaw was found in rubygem-mail's file delivery
method. A remote attacker could use this flaw to send a mail with a
specially crafted To: header and write to files with the privileges of
an application using rubygem-mail. (CVE-2012-2139)

Puppet was updated to version 2.6.17, which fixes multiple security
issues. These issues are not exposed by CloudForms. (CVE-2012-1986,
CVE-2012-1987, CVE-2012-1988, CVE-2012-3864, CVE-2012-3865, CVE-2012-3867)

Red Hat would like to thank Puppet Labs for reporting CVE-2012-1988,
CVE-2012-1986, CVE-2012-1987, CVE-2012-3864, CVE-2012-3865, and
CVE-2012-3867.

Users are advised to upgrade to these CloudForms Commons packages, which
resolve these issues.    </Note>
    <Note Title="Terms of Use" Ordinal="3" Type="Legal Disclaimer" xml:lang="en">Please see https://www.redhat.com/footer/terms-of-use.html</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright © 2012 Red Hat, Inc. All rights reserved.</DocumentDistribution>
  <AggregateSeverity Namespace="https://access.redhat.com/security/updates/classification/">Moderate</AggregateSeverity>
  <DocumentReferences>
    <Reference Type="Self">
       <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL>
       <Description>https://rhn.redhat.com/errata/RHSA-2012-1542.html</Description>
    </Reference>
    <Reference>
       <URL>https://access.redhat.com/security/updates/classification/#moderate</URL>
       <Description>https://access.redhat.com/security/updates/classification/#moderate</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="Red Hat CloudForms">
      <Branch Type="Product Name" Name="Cloud Engine for RHEL 6 Server">
        <FullProductName ProductID="6Server-CloudEngine">Cloud Engine for RHEL 6 Server</FullProductName>
      </Branch>
      <Branch Type="Product Name" Name="System Engine for RHEL 6 Server">
        <FullProductName ProductID="6Server-SystemEngine">System Engine for RHEL 6 Server</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="converge-ui-devel-1.0.4-1.el6cf">
      <FullProductName ProductID="converge-ui-devel-1.0.4-1.el6cf">converge-ui-devel-1.0.4-1.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="puppet-2.6.17-2.el6cf">
      <FullProductName ProductID="puppet-2.6.17-2.el6cf">puppet-2.6.17-2.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-actionpack-3.0.10-10.el6cf">
      <FullProductName ProductID="rubygem-actionpack-3.0.10-10.el6cf">rubygem-actionpack-3.0.10-10.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-activerecord-3.0.10-6.el6cf">
      <FullProductName ProductID="rubygem-activerecord-3.0.10-6.el6cf">rubygem-activerecord-3.0.10-6.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-activesupport-3.0.10-4.el6cf">
      <FullProductName ProductID="rubygem-activesupport-3.0.10-4.el6cf">rubygem-activesupport-3.0.10-4.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-chunky_png-1.2.0-3.el6cf">
      <FullProductName ProductID="rubygem-chunky_png-1.2.0-3.el6cf">rubygem-chunky_png-1.2.0-3.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-compass-0.11.5-2.el6cf">
      <FullProductName ProductID="rubygem-compass-0.11.5-2.el6cf">rubygem-compass-0.11.5-2.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-compass-960-plugin-0.10.4-2.el6cf">
      <FullProductName ProductID="rubygem-compass-960-plugin-0.10.4-2.el6cf">rubygem-compass-960-plugin-0.10.4-2.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-delayed_job-2.1.4-2.el6cf">
      <FullProductName ProductID="rubygem-delayed_job-2.1.4-2.el6cf">rubygem-delayed_job-2.1.4-2.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-ldap_fluff-0.1.3-1.el6_3">
      <FullProductName ProductID="rubygem-ldap_fluff-0.1.3-1.el6_3">rubygem-ldap_fluff-0.1.3-1.el6_3.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-mail-2.3.0-3.el6cf">
      <FullProductName ProductID="rubygem-mail-2.3.0-3.el6cf">rubygem-mail-2.3.0-3.el6cf.src.rpm</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="rubygem-net-ldap-0.1.1-3.el6cf">
      <FullProductName ProductID="rubygem-net-ldap-0.1.1-3.el6cf">rubygem-net-ldap-0.1.1-3.el6cf.src.rpm</FullProductName>
    </Branch>
    <Relationship ProductReference="converge-ui-devel-1.0.4-1.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf">converge-ui-devel-1.0.4-1.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="puppet-2.6.17-2.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:puppet-2.6.17-2.el6cf">puppet-2.6.17-2.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-actionpack-3.0.10-10.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf">rubygem-actionpack-3.0.10-10.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-activerecord-3.0.10-6.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf">rubygem-activerecord-3.0.10-6.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-activesupport-3.0.10-4.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf">rubygem-activesupport-3.0.10-4.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-chunky_png-1.2.0-3.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf">rubygem-chunky_png-1.2.0-3.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-compass-0.11.5-2.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf">rubygem-compass-0.11.5-2.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-compass-960-plugin-0.10.4-2.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf">rubygem-compass-960-plugin-0.10.4-2.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-delayed_job-2.1.4-2.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf">rubygem-delayed_job-2.1.4-2.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-ldap_fluff-0.1.3-1.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3">rubygem-ldap_fluff-0.1.3-1.el6_3 as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-mail-2.3.0-3.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf">rubygem-mail-2.3.0-3.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-net-ldap-0.1.1-3.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-CloudEngine">
      <FullProductName ProductID="6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf">rubygem-net-ldap-0.1.1-3.el6cf as a component of Cloud Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="converge-ui-devel-1.0.4-1.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf">converge-ui-devel-1.0.4-1.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="puppet-2.6.17-2.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:puppet-2.6.17-2.el6cf">puppet-2.6.17-2.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-actionpack-3.0.10-10.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf">rubygem-actionpack-3.0.10-10.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-activerecord-3.0.10-6.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf">rubygem-activerecord-3.0.10-6.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-activesupport-3.0.10-4.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf">rubygem-activesupport-3.0.10-4.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-chunky_png-1.2.0-3.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf">rubygem-chunky_png-1.2.0-3.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-compass-0.11.5-2.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf">rubygem-compass-0.11.5-2.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-compass-960-plugin-0.10.4-2.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf">rubygem-compass-960-plugin-0.10.4-2.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-delayed_job-2.1.4-2.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf">rubygem-delayed_job-2.1.4-2.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-ldap_fluff-0.1.3-1.el6_3" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3">rubygem-ldap_fluff-0.1.3-1.el6_3 as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-mail-2.3.0-3.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf">rubygem-mail-2.3.0-3.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
    <Relationship ProductReference="rubygem-net-ldap-0.1.1-3.el6cf" RelationType="Default Component Of" RelatesToProductReference="6Server-SystemEngine">
      <FullProductName ProductID="6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf">rubygem-net-ldap-0.1.1-3.el6cf as a component of System Engine for RHEL 6 Server</FullProductName>
    </Relationship>
  </ProductTree>

  <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puppet was updated to version 2.6.17, which fixes multiple security issues. These issues are not exposed by CloudForms. </Note></Notes>
    <DiscoveryDate>2012-04-04T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-04-10T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-1986</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>3.6</BaseScore>
      <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://puppetlabs.com/security/cve/cve-2012-1986/</URL>
        <Description>http://puppetlabs.com/security/cve/cve-2012-1986/</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-1986.html</URL>
        <Description>CVE-2012-1986</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=810069</URL>
        <Description>bz#810069: CVE-2012-1986 puppet: Filebucket arbitrary file read</Description>
      </Reference>
    </References>
    <Acknowledgments><Acknowledgment><Description>Red Hat would like to thank Puppet Labs for reporting this issue.</Description></Acknowledgment></Acknowledgments>
  </Vulnerability>

  <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puppet was updated to version 2.6.17, which fixes multiple security issues. These issues are not exposed by CloudForms. </Note></Notes>
    <DiscoveryDate>2012-04-04T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-04-10T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-1987</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>3.5</BaseScore>
      <Vector>AV:N/AC:M/Au:S/C:N/I:N/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://puppetlabs.com/security/cve/cve-2012-1987/</URL>
        <Description>http://puppetlabs.com/security/cve/cve-2012-1987/</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-1987.html</URL>
        <Description>CVE-2012-1987</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=810070</URL>
        <Description>bz#810070: CVE-2012-1987 puppet: Filebucket denial of service</Description>
      </Reference>
    </References>
    <Acknowledgments><Acknowledgment><Description>Red Hat would like to thank Puppet Labs for reporting this issue.</Description></Acknowledgment></Acknowledgments>
  </Vulnerability>

  <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puppet was updated to version 2.6.17, which fixes multiple security issues. These issues are not exposed by CloudForms. </Note></Notes>
    <DiscoveryDate>2012-04-04T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-04-10T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-1988</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>6.0</BaseScore>
      <Vector>AV:N/AC:M/Au:S/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://puppetlabs.com/security/cve/cve-2012-1988/</URL>
        <Description>http://puppetlabs.com/security/cve/cve-2012-1988/</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-1988.html</URL>
        <Description>CVE-2012-1988</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=810071</URL>
        <Description>bz#810071: CVE-2012-1988 puppet: Filebucket arbitrary code execution</Description>
      </Reference>
    </References>
    <Acknowledgments><Acknowledgment><Description>Red Hat would like to thank Puppet Labs for reporting this issue.</Description></Acknowledgment></Acknowledgments>
  </Vulnerability>

  <Vulnerability Ordinal="4" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A directory traversal flaw was found in rubygem-mail's file delivery method. A remote attacker could use this flaw to send a mail with a specially crafted To: header and write to files with the privileges of an application using rubygem-mail. </Note></Notes>
    <DiscoveryDate>2012-04-25T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-03-14T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-2139</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>7.5</BaseScore>
      <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-2139.html</URL>
        <Description>CVE-2012-2139</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=816352</URL>
        <Description>bz#816352: CVE-2012-2139 CVE-2012-2140 rubygem-mail: arbitrary command execution when using exim or sendmail from commandline, file system traversal flaw</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="5" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An input validation flaw was found in rubygem-mail's Exim and Sendmail delivery methods. A remote attacker could use this flaw to execute arbitrary commands with the privileges of an application using rubygem-mail. </Note></Notes>
    <DiscoveryDate>2012-04-25T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-03-14T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-2140</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>7.5</BaseScore>
      <Vector>AV:N/AC:L/Au:N/C:P/I:P/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-2140.html</URL>
        <Description>CVE-2012-2140</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="6" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple input validation vulnerabilities were discovered in rubygem-activerecored. A remote attacker could possibly use these flaws to perform an SQL injection attack against an application using rubygem-activerecord. </Note></Notes>
    <DiscoveryDate>2012-05-31T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-05-31T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-2660</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.0</BaseScore>
      <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-2660.html</URL>
        <Description>CVE-2012-2660</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=827353</URL>
        <Description>bz#827353: CVE-2012-2660 rubygem-actionpack: Unsafe query generation</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="7" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple input validation vulnerabilities were discovered in rubygem-activerecored. A remote attacker could possibly use these flaws to perform an SQL injection attack against an application using rubygem-activerecord. </Note></Notes>
    <DiscoveryDate>2012-05-31T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-05-31T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-2661</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-2661.html</URL>
        <Description>CVE-2012-2661</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=827363</URL>
        <Description>bz#827363: CVE-2012-2661 rubygem-activerecord: SQL injection when processing nested query paramaters</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="8" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple input validation vulnerabilities were discovered in rubygem-activerecored. A remote attacker could possibly use these flaws to perform an SQL injection attack against an application using rubygem-activerecord. </Note></Notes>
    <DiscoveryDate>2012-06-12T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-06-12T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-2694</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.0</BaseScore>
      <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-2694.html</URL>
        <Description>CVE-2012-2694</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=831581</URL>
        <Description>bz#831581: CVE-2012-2694 rubygem-actionpack: Unsafe query generation (a different flaw than CVE-2012-2660)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="9" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple input validation vulnerabilities were discovered in rubygem-activerecored. A remote attacker could possibly use these flaws to perform an SQL injection attack against an application using rubygem-activerecord. </Note></Notes>
    <DiscoveryDate>2012-06-12T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-06-12T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-2695</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:P/I:N/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-2695.html</URL>
        <Description>CVE-2012-2695</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=831573</URL>
        <Description>bz#831573: CVE-2012-2695 rubygem-activerecord: SQL injection when processing nested query paramaters (a different flaw than CVE-2012-2661)</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="10" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the HTTP digest authentication implementation in rubygem-actionpack. A remote attacker could use this flaw to cause a denial of service of an application using rubygem-actionpack and digest authentication. </Note></Notes>
    <DiscoveryDate>2012-07-26T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-07-26T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-3424</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:N/I:N/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-3424.html</URL>
        <Description>CVE-2012-3424</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=843711</URL>
        <Description>bz#843711: CVE-2012-3424 rubygem-actionpack: DoS vulnerability in authenticate_or_request_with_http_digest</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="11" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple cross-site scripting (XSS) flaws were found in rubygem-actionpack. A remote attacker could use these flaws to conduct XSS attacks against users of an application using rubygem-actionpack. </Note></Notes>
    <DiscoveryDate>2012-08-09T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-08-09T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-3463</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-3463.html</URL>
        <Description>CVE-2012-3463</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=847196</URL>
        <Description>bz#847196: CVE-2012-3463 rubygem-actionpack: potential XSS vulnerability in select_tag prompt</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="12" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple cross-site scripting (XSS) flaws were found in rubygem-actionpack. A remote attacker could use these flaws to conduct XSS attacks against users of an application using rubygem-actionpack. </Note></Notes>
    <DiscoveryDate>2012-08-09T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-08-09T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-3464</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-3464.html</URL>
        <Description>CVE-2012-3464</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=847199</URL>
        <Description>bz#847199: CVE-2012-3464 rubygem-actionpack: potential XSS vulnerability</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="13" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Multiple cross-site scripting (XSS) flaws were found in rubygem-actionpack. A remote attacker could use these flaws to conduct XSS attacks against users of an application using rubygem-actionpack. </Note></Notes>
    <DiscoveryDate>2012-08-09T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-08-09T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-3465</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Moderate</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.3</BaseScore>
      <Vector>AV:N/AC:M/Au:N/C:N/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-3465.html</URL>
        <Description>CVE-2012-3465</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=847200</URL>
        <Description>bz#847200: CVE-2012-3465 rubygem-actionpack: XSS Vulnerability in strip_tags</Description>
      </Reference>
    </References>
  </Vulnerability>

  <Vulnerability Ordinal="14" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puppet was updated to version 2.6.17, which fixes multiple security issues. These issues are not exposed by CloudForms. </Note></Notes>
    <DiscoveryDate>2012-07-06T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-07-10T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-3864</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>2.1</BaseScore>
      <Vector>AV:N/AC:H/Au:S/C:P/I:N/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://puppetlabs.com/security/cve/cve-2012-3864/</URL>
        <Description>http://puppetlabs.com/security/cve/cve-2012-3864/</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-3864.html</URL>
        <Description>CVE-2012-3864</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=839130</URL>
        <Description>bz#839130: CVE-2012-3864 puppet: authenticated clients allowed to read arbitrary files from the puppet master</Description>
      </Reference>
    </References>
    <Acknowledgments><Acknowledgment><Description>Red Hat would like to thank Puppet Labs for reporting this issue.</Description></Acknowledgment></Acknowledgments>
  </Vulnerability>

  <Vulnerability Ordinal="15" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puppet was updated to version 2.6.17, which fixes multiple security issues. These issues are not exposed by CloudForms. </Note></Notes>
    <DiscoveryDate>2012-07-06T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-07-10T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-3865</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>2.1</BaseScore>
      <Vector>AV:N/AC:H/Au:S/C:N/I:N/A:P</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://puppetlabs.com/security/cve/cve-2012-3865/</URL>
        <Description>http://puppetlabs.com/security/cve/cve-2012-3865/</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-3865.html</URL>
        <Description>CVE-2012-3865</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=839131</URL>
        <Description>bz#839131: CVE-2012-3865 puppet: authenticated clients allowed to delete arbitrary files on the puppet master</Description>
      </Reference>
    </References>
    <Acknowledgments><Acknowledgment><Description>Red Hat would like to thank Puppet Labs for reporting this issue.</Description></Acknowledgment></Acknowledgments>
  </Vulnerability>

  <Vulnerability Ordinal="16" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
    <Notes><Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Puppet was updated to version 2.6.17, which fixes multiple security issues. These issues are not exposed by CloudForms. </Note></Notes>
    <DiscoveryDate>2012-07-06T00:00:00Z</DiscoveryDate>
    <ReleaseDate>2012-07-10T00:00:00Z</ReleaseDate>
    <Involvements><Involvement Party="Vendor" Status="Completed"></Involvement></Involvements>
    <CVE>CVE-2012-3867</CVE>
    <ProductStatuses><Status Type="Fixed">
      <ProductID>6Server-CloudEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-CloudEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:converge-ui-devel-1.0.4-1.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:puppet-2.6.17-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-actionpack-3.0.10-10.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activerecord-3.0.10-6.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-activesupport-3.0.10-4.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-chunky_png-1.2.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-0.11.5-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-compass-960-plugin-0.10.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-delayed_job-2.1.4-2.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-ldap_fluff-0.1.3-1.el6_3</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-mail-2.3.0-3.el6cf</ProductID>
      <ProductID>6Server-SystemEngine:rubygem-net-ldap-0.1.1-3.el6cf</ProductID>
    </Status></ProductStatuses>
    <Threats><Threat Type="Impact"><Description>Low</Description></Threat></Threats>
    <CVSSScoreSets><ScoreSet>
      <BaseScore>4.0</BaseScore>
      <Vector>AV:N/AC:H/Au:N/C:P/I:P/A:N</Vector>
    </ScoreSet></CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix"><Description xml:lang="en">
Before applying this update, make sure all previously-released errata
relevant to your system have been applied.

This update is available via the Red Hat Network. Details on how to
use the Red Hat Network to apply this update are available at
https://access.redhat.com/knowledge/articles/11258    </Description>      <URL>https://rhn.redhat.com/errata/RHSA-2012-1542.html</URL></Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>http://puppetlabs.com/security/cve/cve-2012-3867/</URL>
        <Description>http://puppetlabs.com/security/cve/cve-2012-3867/</Description>
      </Reference>
      <Reference>
        <URL>https://www.redhat.com/security/data/cve/CVE-2012-3867.html</URL>
        <Description>CVE-2012-3867</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.redhat.com/show_bug.cgi?id=839158</URL>
        <Description>bz#839158: CVE-2012-3867 puppet: insufficient validation of agent names in CN of SSL certificate requests</Description>
      </Reference>
    </References>
    <Acknowledgments><Acknowledgment><Description>Red Hat would like to thank Puppet Labs for reporting this issue.</Description></Acknowledgment></Acknowledgments>
  </Vulnerability>
</cvrfdoc>
