10 High
CVSS2
Attack Vector
NETWORK
Attack Complexity
LOW
Authentication
NONE
Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
AV:N/AC:L/Au:N/C:C/I:C/A:C
7.1 High
AI Score
Confidence
Low
0.099 Low
EPSS
Percentile
94.9%
Debian Security Advisory DSA-2620-1 [email protected]
http://www.debian.org/security/ Florian Weimer
February 12, 2013 http://www.debian.org/security/faq
Package : rails
Vulnerability : several
Problem type : remote
Debian-specific: no
CVE ID : CVE-2013-0276 CVE-2013-0277
Two vulnerabilities were discovered in Ruby on Rails, a Ruby framework
for web application development.
CVE-2013-0276
The blacklist provided by the attr_protected method could be
bypassed with crafted requests, having an application-specific
impact.
CVE-2013-0277
In some applications, the +serialize+ helper in ActiveRecord
could be tricked into deserializing arbitrary YAML data,
possibly leading to remote code execution.
For the stable distribution (squeeze), these problems have been fixed
in version 2.3.5-1.2+squeeze7.
We recommend that you upgrade your rails packages.
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/
Mailing list: [email protected]
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Debian | 6 | all | rails | <ย 2.3.5-1.2+squeeze7 | rails_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | libactiverecord-ruby1.9.1 | <ย 2.3.5-1.2+squeeze7 | libactiverecord-ruby1.9.1_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | libactiveresource-ruby | <ย 2.3.5-1.2+squeeze7 | libactiveresource-ruby_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | rails-doc | <ย 2.3.5-1.2+squeeze7 | rails-doc_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | libactionpack-ruby1.8 | <ย 2.3.5-1.2+squeeze7 | libactionpack-ruby1.8_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | libactiverecord-ruby | <ย 2.3.5-1.2+squeeze7 | libactiverecord-ruby_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | libactivesupport-ruby1.9.1 | <ย 2.3.5-1.2+squeeze7 | libactivesupport-ruby1.9.1_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | libactivesupport-ruby | <ย 2.3.5-1.2+squeeze7 | libactivesupport-ruby_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | libactionmailer-ruby | <ย 2.3.5-1.2+squeeze7 | libactionmailer-ruby_2.3.5-1.2+squeeze7_all.deb |
Debian | 6 | all | rails-ruby1.8 | <ย 2.3.5-1.2+squeeze7 | rails-ruby1.8_2.3.5-1.2+squeeze7_all.deb |