Revision Date: | 2013-03-19 | Version: | 1 | Title: | CVE-2013-1854 on Ubuntu 16.04 LTS (xenial) - medium. | Description: | The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.
| Family: | unix | Class: | vulnerability | Status: | | Reference(s): | CVE-2013-1854
| Platform(s): | Ubuntu 16.04 LTS
| Product(s): | | Definition Synopsis | Ubuntu 16.04 LTS (xenial) is installed. AND Package Information
NOT rails package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-actionmailer package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-actionpack package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-actionview package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-activejob package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-activemodel package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-activerecord package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-activesupport package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-rails package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
OR NOT ruby-railties package in xenial, while related to the CVE in some way, is not affected (note: 'contains no code').
|
|