LWN.net Logo

rails: multiple vulnerabilities

Package(s):RubyOnRails CVE #(s):CVE-2013-0262 CVE-2013-0263
Created:February 25, 2013 Updated:March 15, 2013
Description: From the CVE entries:

rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals." (CVE-2013-0262)

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving am HMAC comparison function that does not run in constant time. (CVE-2013-0263)

Alerts:
openSUSE openSUSE-SU-2013:0338-1 2013-02-25
Red Hat RHSA-2013:0638-01 2013-03-12
openSUSE openSUSE-SU-2013:0462-1 2013-03-14

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds