Vulnerability   
Search   
    Search 191973 CVE descriptions
and 86218 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.702620
Category:Debian Local Security Checks
Title:Debian Security Advisory DSA 2620-1 (rails - several vulnerabilities)
Summary:Two vulnerabilities were discovered in Ruby on Rails, a Ruby framework;for web application development.;;CVE-2013-0276;The blacklist provided by the attr_protected method could be;bypassed with crafted requests, having an application-specific;impact.;;CVE-2013-0277;In some applications, the +serialize+ helper in ActiveRecord;could be tricked into deserializing arbitrary YAML data,;possibly leading to remote code execution.
Description:Summary:
Two vulnerabilities were discovered in Ruby on Rails, a Ruby framework
for web application development.

CVE-2013-0276
The blacklist provided by the attr_protected method could be
bypassed with crafted requests, having an application-specific
impact.

CVE-2013-0277
In some applications, the +serialize+ helper in ActiveRecord
could be tricked into deserializing arbitrary YAML data,
possibly leading to remote code execution.

Affected Software/OS:
rails on Debian Linux

Solution:
For the stable distribution (squeeze), these problems have been fixed
in version 2.3.5-1.2+squeeze7.

We recommend that you upgrade your rails packages.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2013-0276
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
BugTraq ID: 57896
http://www.securityfocus.com/bid/57896
Debian Security Information: DSA-2620 (Google Search)
http://www.debian.org/security/2013/dsa-2620
http://www.openwall.com/lists/oss-security/2013/02/11/5
https://groups.google.com/group/rubyonrails-security/msg/bb44b98a73ef1a06?dmode=source&output=gplain
http://www.osvdb.org/90072
RedHat Security Advisories: RHSA-2013:0686
http://rhn.redhat.com/errata/RHSA-2013-0686.html
http://secunia.com/advisories/52112
http://secunia.com/advisories/52774
SuSE Security Announcement: openSUSE-SU-2013:0462 (Google Search)
http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
Common Vulnerability Exposure (CVE) ID: CVE-2013-0277
http://www.openwall.com/lists/oss-security/2013/02/11/6
https://groups.google.com/group/rubyonrails-security/msg/302ec7ce90f13837?dmode=source&output=gplain
http://www.osvdb.org/90073
http://securitytracker.com/id?1028109
CopyrightCopyright (C) 2013 Greenbone Networks GmbH http://greenbone.net

This is only one of 86218 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2020 E-Soft Inc. All rights reserved.