LWN.net Logo

rubygem-activerecord: SQL injection

Package(s):rubygem-activerecord CVE #(s):CVE-2012-2695
Created:July 2, 2012 Updated:August 21, 2012
Description: From the CVE entry:

The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage improper handling of nested hashes, a related issue to CVE-2012-2661.

Alerts:
Fedora FEDORA-2012-9635 2012-06-30
Fedora FEDORA-2012-9639 2012-06-30
openSUSE openSUSE-SU-2012:0978-1 2012-08-09
SUSE SUSE-SU-2012:1011-1 2012-08-21
SUSE SUSE-SU-2012:1012-1 2012-08-21
SUSE SUSE-SU-2012:1014-1 2012-08-21
openSUSE openSUSE-SU-2012:1066-1 2012-08-30
openSUSE openSUSE-SU-2013:0278-1 2013-02-12
openSUSE openSUSE-SU-2013:0280-1 2013-02-12
Red Hat RHSA-2013:0582-01 2013-02-28
SUSE SUSE-SU-2013:0508-1 2013-03-20

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds