LWN.net Logo

ruby: denial of service

Package(s):ruby1.9.1 CVE #(s):CVE-2013-0269
Created:February 21, 2013 Updated:April 4, 2013
Description: From the CVE entry:

The JSON gem 1.7.x before 1.7.7, 1.6.x before 1.6.8, and 1.5.x before 1.5.5 allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."

Alerts:
Ubuntu USN-1733-1 2013-02-21
Fedora FEDORA-2013-3052 2013-03-05
Fedora FEDORA-2013-3050 2013-03-05
Slackware SSA:2013-075-01 2013-03-16
Red Hat RHSA-2013:0701-01 2013-04-02
openSUSE openSUSE-SU-2013:0603-1 2013-04-03
SUSE SUSE-SU-2013:0609-1 2013-04-03
SUSE SUSE-SU-2013:0612-1 2013-04-03
SUSE SUSE-SU-2013:0615-1 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds