LWN.net Logo

rubygem-actionpack: restriction bypass

Package(s):rubygem-actionpack CVE #(s):CVE-2012-2694
Created:July 2, 2012 Updated:August 21, 2012
Description: From the CVE entry:

actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks via a crafted request, as demonstrated by certain "['xyz', nil]" values, a related issue to CVE-2012-2660.

Alerts:
Fedora FEDORA-2012-9606 2012-06-30
Fedora FEDORA-2012-9636 2012-06-30
openSUSE openSUSE-SU-2012:0978-1 2012-08-09
SUSE SUSE-SU-2012:1012-1 2012-08-21
SUSE SUSE-SU-2012:1014-1 2012-08-21
SUSE SUSE-SU-2012:1015-1 2012-08-21
openSUSE openSUSE-SU-2012:1066-1 2012-08-30
Red Hat RHSA-2013:0582-01 2013-02-28

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds