Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702620
Category:Debian Local Security Checks
Title:Debian: Security Advisory (DSA-2620-1)
Summary:The remote host is missing an update for the Debian 'rails' package(s) announced via the DSA-2620-1 advisory.
Description:Summary:
The remote host is missing an update for the Debian 'rails' package(s) announced via the DSA-2620-1 advisory.

Vulnerability Insight:
Two vulnerabilities were discovered in Ruby on Rails, a Ruby framework for web application development.

CVE-2013-0276

The blacklist provided by the attr_protected method could be bypassed with crafted requests, having an application-specific impact.

CVE-2013-0277

In some applications, the +serialize+ helper in ActiveRecord could be tricked into deserializing arbitrary YAML data, possibly leading to remote code execution.

For the stable distribution (squeeze), these problems have been fixed in version 2.3.5-1.2+squeeze7.

We recommend that you upgrade your rails packages.

Affected Software/OS:
'rails' package(s) on Debian 6.

Solution:
Please install the updated package(s).

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-0276
52112
http://secunia.com/advisories/52112
52774
http://secunia.com/advisories/52774
57896
http://www.securityfocus.com/bid/57896
90072
http://www.osvdb.org/90072
APPLE-SA-2013-06-04-1
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
DSA-2620
http://www.debian.org/security/2013/dsa-2620
RHSA-2013:0686
http://rhn.redhat.com/errata/RHSA-2013-0686.html
[oss-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]
http://www.openwall.com/lists/oss-security/2013/02/11/5
[rubyonrails-security] 20130211 Circumvention of attr_protected [CVE-2013-0276]
https://groups.google.com/group/rubyonrails-security/msg/bb44b98a73ef1a06?dmode=source&output=gplain
http://support.apple.com/kb/HT5784
http://weblog.rubyonrails.org/2013/2/11/SEC-ANN-Rails-3-2-12-3-1-11-and-2-3-17-have-been-released/
openSUSE-SU-2013:0462
http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-0277
1028109
http://securitytracker.com/id?1028109
90073
http://www.osvdb.org/90073
[oss-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
http://www.openwall.com/lists/oss-security/2013/02/11/6
[rubyonrails-security] 20130211 Serialized Attributes YAML Vulnerability with Rails 2.3 and 3.0 [CVE-2013-0277]
https://groups.google.com/group/rubyonrails-security/msg/302ec7ce90f13837?dmode=source&output=gplain
https://puppet.com/security/cve/cve-2013-0277
CopyrightCopyright (C) 2013 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.