LWN.net Logo

rails: protection bypass/code execution

Package(s):rails CVE #(s):CVE-2013-0276 CVE-2013-0277
Created:February 13, 2013 Updated:March 15, 2013
Description: From the CVE entries:

ActiveRecord in Ruby on Rails 3.2.x before 3.2.12, 3.1.x before 3.1.11, and 2.3.x before 2.3.17 allows remote attackers to bypass the attr_protected protection mechanism and modify protected model attributes via a crafted request. (CVE-2013-0276)

Active Record in Ruby on Rails 3.x before 3.1.0 and 2.3.x before 2.3.17 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML. (CVE-2013-0277)

Alerts:
Debian DSA-2620-1 2013-02-12
Fedora FEDORA-2013-2398 2013-02-21
Fedora FEDORA-2013-2391 2013-02-21
Fedora FEDORA-2013-2351 2013-02-21
openSUSE openSUSE-SU-2013:0338-1 2013-02-25
openSUSE openSUSE-SU-2013:0462-1 2013-03-14
SUSE SUSE-SU-2013:0486-1 2013-03-19
SUSE SUSE-SU-2013:0606-1 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds