LWN.net Logo

rubygem-activesupport: multiple vulnerabilities

Package(s):rubygem-activesupport CVE #(s):CVE-2013-0333
Created:January 29, 2013 Updated:February 10, 2013
Description: From the Red Hat advisory:

A flaw was found in the way Active Support performed the parsing of JSON requests by translating them to YAML. A remote attacker could use this flaw to execute arbitrary code with the privileges of a Ruby on Rails application, perform SQL injection attacks, or bypass the authentication using a specially-created JSON request.

Alerts:
Red Hat RHSA-2013:0202-01 2013-01-28
Debian DSA-2613-1 2013-01-30
Fedora FEDORA-2013-1745 2013-02-10
Fedora FEDORA-2013-1710 2013-02-10
openSUSE openSUSE-SU-2013:0278-1 2013-02-12
openSUSE openSUSE-SU-2013:0280-1 2013-02-12
SUSE SUSE-SU-2013:0486-1 2013-03-19
SUSE SUSE-SU-2013:0606-1 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds