Oval Definition:oval:com.ubuntu.precise:def:20133221000
Revision Date:2013-04-21Version:1
Title:CVE-2013-3221 on Ubuntu 12.04 LTS (precise) - medium.
Description:The Active Record component in Ruby on Rails 2.3.x, 3.0.x, 3.1.x, and 3.2.x does not ensure that the declared data type of a database column is used during comparisons of input values to stored values in that column, which makes it easier for remote attackers to conduct data-type injection attacks against Ruby on Rails applications via a crafted value, as demonstrated by unintended interaction between the "typed XML" feature and a MySQL database.
Family:unixClass:vulnerability
Status:Reference(s):CVE-2013-3221
Platform(s):Ubuntu 12.04 LTS
Product(s):
Definition Synopsis
  • Ubuntu 12.04 LTS (precise) is installed.
  • AND The vulnerability of the 'ruby-activerecord-2.3' package in precise is not known (status: 'needs-triage'). It is pending evaluation.
  • BACK