Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2013-1854
Description:The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
Test IDs: None available
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2013-1854
APPLE-SA-2013-06-04-1
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
APPLE-SA-2013-10-22-5
http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html
RHSA-2013:0699
http://rhn.redhat.com/errata/RHSA-2013-0699.html
RHSA-2014:1863
http://rhn.redhat.com/errata/RHSA-2014-1863.html
[ruby-security-ann] 20130318 [CVE-2013-1854] Symbol DoS vulnerability in Active Record
https://groups.google.com/group/ruby-security-ann/msg/34e0d780b04308de?dmode=source&output=gplain
http://support.apple.com/kb/HT5784
http://support.apple.com/kb/HT5784
http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/
http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/
openSUSE-SU-2013:0659
http://lists.opensuse.org/opensuse-updates/2013-04/msg00070.html
openSUSE-SU-2013:0660
http://lists.opensuse.org/opensuse-updates/2013-04/msg00071.html
openSUSE-SU-2013:0664
http://lists.opensuse.org/opensuse-updates/2013-04/msg00075.html
openSUSE-SU-2013:0667
http://lists.opensuse.org/opensuse-updates/2013-04/msg00078.html
openSUSE-SU-2013:0668
http://lists.opensuse.org/opensuse-updates/2013-04/msg00079.html




© 1998-2025 E-Soft Inc. All rights reserved.