LWN.net Logo

rails: privilege escalation

Package(s):rails CVE #(s):CVE-2013-0155
Created:January 17, 2013 Updated:January 23, 2013
Description:

From the Debian advisory:

An interpretation conflict can cause the Active Record component of Rails, a web framework for the Ruby programming language, to truncate queries in unexpected ways. This may allow attackers to elevate their privileges.

Alerts:
Debian DSA-2609-1 2013-01-16
Fedora FEDORA-2013-0568 2013-01-20
Fedora FEDORA-2013-0568 2013-01-20
Fedora FEDORA-2013-0568 2013-01-20
Fedora FEDORA-2013-0635 2013-01-23
Fedora FEDORA-2013-0686 2013-01-23
Fedora FEDORA-2013-0635 2013-01-23
Fedora FEDORA-2013-0686 2013-01-23
Fedora FEDORA-2013-0635 2013-01-23
Fedora FEDORA-2013-0686 2013-01-23
Fedora FEDORA-2013-0635 2013-01-23
Fedora FEDORA-2013-0686 2013-01-23
openSUSE openSUSE-SU-2013:0278-1 2013-02-12
openSUSE openSUSE-SU-2013:0280-1 2013-02-12
Red Hat RHSA-2013:0582-01 2013-02-28
SUSE SUSE-SU-2013:0486-1 2013-03-19
SUSE SUSE-SU-2013:0508-1 2013-03-20
SUSE SUSE-SU-2013:0606-1 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds