LWN.net Logo

rubygem-multi_xml: code execution

Package(s):rubygem-multi_xml CVE #(s):CVE-2013-0175
Created:January 25, 2013 Updated:January 30, 2013
Description:

From the Red Hat bugzilla entry:

A security flaw was found in the way multi_xml gem, a Ruby gem to provide swappable XML backends utilizing LibXML, Nokogiri, Ox, or REXML, performed Symbol and YAML parameters parsing. A remote attacker could use this flaw to execute arbitrary code with the privileges of the Ruby on Rails application using the multi_xml gem via specially-crafted HTTP POST request.

Alerts:
Fedora FEDORA-2013-0808 2013-01-24
Fedora FEDORA-2013-0839 2013-01-25

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds