Vulnerability Name:

CVE-2014-0082 (CCN-91169)

Assigned:2013-12-03
Published:2014-02-18
Updated:2019-08-08
Summary:actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
CVSS v3 Severity:5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-20
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2014-0082

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2014:0295

Source: MLIST
Type: UNKNOWN
[oss-security] 20140218 Denial of Service Vulnerability in Action View when using render :text (CVE-2014-0082)

Source: CCN
Type: Puppet Labs Web Site
CVE-2014-0082 (ActionView vulnerability in Ruby on Rails)

Source: REDHAT
Type: UNKNOWN
RHSA-2014:0215

Source: REDHAT
Type: UNKNOWN
RHSA-2014:0306

Source: CCN
Type: SA56964
Ruby on Rails Multiple Vulnerabilities

Source: CCN
Type: SA57159
Puppet Enterprise Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
57376

Source: CCN
Type: SA57836
Chef Multiple Vulnerabilities

Source: SECUNIA
Type: UNKNOWN
57836

Source: CCN
Type: Ruby on Rails Web Site
Rails 3.2.17, 4.0.3 and 4.1.0.beta2 have been released!

Source: CONFIRM
Type: UNKNOWN
http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/

Source: CCN
Type: BID-65604
Ruby on Rails CVE-2014-0082 Denial of Service Vulnerability

Source: XF
Type: UNKNOWN
rubyonrails-cve20140082-dos(91169)

Source: MLIST
Type: UNKNOWN
[rubyonrails-security] 20140218 Denial of Service Vulnerability in Action View when using render :text (CVE-2014-0082)

Source: CONFIRM
Type: UNKNOWN
https://puppet.com/security/cve/cve-2014-0082

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-0082

Vulnerable Configuration:Configuration 1:
  • cpe:/a:rubyonrails:rails:3.0.0:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.0:beta:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.0:beta2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.0:beta3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.0:beta4:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.0:rc:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.1:-:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.1:pre:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.2:-:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.2:pre:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.4:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.5:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.6:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.6:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.6:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.7:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.7:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.7:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.8:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.8:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.8:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.8:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.8:rc4:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.9:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.9:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.9:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.9:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.9:rc4:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.9:rc5:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.10:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.10:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.11:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.12:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.12:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.13:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.13:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.14:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.16:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.17:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.18:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.19:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.20:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:beta1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:rc4:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:rc5:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:rc6:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:rc7:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.0:rc8:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.1:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.1:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.1:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.2:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.2:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.4:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.4:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.5:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.5:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.6:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.7:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.8:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.9:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.1.10:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.0:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.0:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.0:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.1:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.2:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.2:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.3:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.3:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.3:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.4:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.4:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.5:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.6:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.7:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.8:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.9:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.10:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.11:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.12:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.13:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.13:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.13:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.15:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.2.15:rc3:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:rails:3.0.4:-:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:3.2.14:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:3.2.14:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:3.2.14:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:3.2.15:rc1:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:3.2.15:rc2:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* (Version <= 3.2.16)

  • Configuration CCN 1:
  • cpe:/a:rubyonrails:rails:3.2.16:*:*:*:*:*:*:*
  • OR cpe:/a:rubyonrails:ruby_on_rails:4.0.2:*:*:*:*:*:*:*
  • AND
  • cpe:/a:puppetlabs:puppet:3.1.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:26181
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:26117
    P
    Security update for xen (Important)
    2021-09-02
    oval:org.opensuse.security:def:26106
    P
    Security update for libmspack (Moderate)
    2021-08-17
    oval:org.opensuse.security:def:26105
    P
    Security update for MozillaFirefox (Important)
    2021-08-17
    oval:org.opensuse.security:def:20140082
    V
    CVE-2014-0082
    2021-08-15
    oval:org.opensuse.security:def:36556
    P
    rubygem-actionpack-3_2-3.2.12-0.19.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:26823
    P
    star on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26309
    P
    Security update for haproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:27554
    P
    rubygem-actionpack-3_2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26682
    P
    cyrus-imapd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26837
    P
    vte on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26390
    P
    Security update for ark (Low)
    2020-12-01
    oval:org.opensuse.security:def:26735
    P
    libMagickCore1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26881
    P
    dbus-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26447
    P
    Security update for pdns (Important)
    2020-12-01
    oval:org.opensuse.security:def:26784
    P
    mono-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27519
    P
    nagios on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:26531
    P
    coolkey on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.cosmic:def:201400820000000
    V
    CVE-2014-0082 on Ubuntu 18.10 (cosmic) - medium.
    2014-02-20
    oval:com.ubuntu.artful:def:20140082000
    V
    CVE-2014-0082 on Ubuntu 17.10 (artful) - medium.
    2014-02-20
    oval:com.ubuntu.trusty:def:20140082000
    V
    CVE-2014-0082 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-02-20
    oval:com.ubuntu.bionic:def:201400820000000
    V
    CVE-2014-0082 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-02-20
    oval:com.ubuntu.bionic:def:20140082000
    V
    CVE-2014-0082 on Ubuntu 18.04 LTS (bionic) - medium.
    2014-02-20
    oval:com.ubuntu.xenial:def:20140082000
    V
    CVE-2014-0082 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-02-20
    oval:com.ubuntu.xenial:def:201400820000000
    V
    CVE-2014-0082 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-02-20
    oval:com.ubuntu.cosmic:def:20140082000
    V
    CVE-2014-0082 on Ubuntu 18.10 (cosmic) - medium.
    2014-02-20
    oval:com.ubuntu.precise:def:20140082000
    V
    CVE-2014-0082 on Ubuntu 12.04 LTS (precise) - medium.
    2014-02-20
    BACK
    rubyonrails rails 3.0.0
    rubyonrails rails 3.0.0 beta
    rubyonrails rails 3.0.0 beta2
    rubyonrails rails 3.0.0 beta3
    rubyonrails rails 3.0.0 beta4
    rubyonrails rails 3.0.0 rc
    rubyonrails rails 3.0.0 rc2
    rubyonrails rails 3.0.1
    rubyonrails rails 3.0.1 pre
    rubyonrails rails 3.0.2
    rubyonrails rails 3.0.2 pre
    rubyonrails rails 3.0.3
    rubyonrails rails 3.0.4 rc1
    rubyonrails rails 3.0.5
    rubyonrails rails 3.0.5 rc1
    rubyonrails rails 3.0.6
    rubyonrails rails 3.0.6 rc1
    rubyonrails rails 3.0.6 rc2
    rubyonrails rails 3.0.7
    rubyonrails rails 3.0.7 rc1
    rubyonrails rails 3.0.7 rc2
    rubyonrails rails 3.0.8
    rubyonrails rails 3.0.8 rc1
    rubyonrails rails 3.0.8 rc2
    rubyonrails rails 3.0.8 rc3
    rubyonrails rails 3.0.8 rc4
    rubyonrails rails 3.0.9
    rubyonrails rails 3.0.9 rc1
    rubyonrails rails 3.0.9 rc2
    rubyonrails rails 3.0.9 rc3
    rubyonrails rails 3.0.9 rc4
    rubyonrails rails 3.0.9 rc5
    rubyonrails rails 3.0.10
    rubyonrails rails 3.0.10 rc1
    rubyonrails rails 3.0.11
    rubyonrails rails 3.0.12
    rubyonrails rails 3.0.12 rc1
    rubyonrails rails 3.0.13
    rubyonrails rails 3.0.13 rc1
    rubyonrails rails 3.0.14
    rubyonrails rails 3.0.16
    rubyonrails rails 3.0.17
    rubyonrails rails 3.0.18
    rubyonrails rails 3.0.19
    rubyonrails rails 3.0.20
    rubyonrails rails 3.1.0
    rubyonrails rails 3.1.0 beta1
    rubyonrails rails 3.1.0 rc1
    rubyonrails rails 3.1.0 rc2
    rubyonrails rails 3.1.0 rc3
    rubyonrails rails 3.1.0 rc4
    rubyonrails rails 3.1.0 rc5
    rubyonrails rails 3.1.0 rc6
    rubyonrails rails 3.1.0 rc7
    rubyonrails rails 3.1.0 rc8
    rubyonrails rails 3.1.1
    rubyonrails rails 3.1.1 rc1
    rubyonrails rails 3.1.1 rc2
    rubyonrails rails 3.1.1 rc3
    rubyonrails rails 3.1.2
    rubyonrails rails 3.1.2 rc1
    rubyonrails rails 3.1.2 rc2
    rubyonrails rails 3.1.3
    rubyonrails rails 3.1.4
    rubyonrails rails 3.1.4 rc1
    rubyonrails rails 3.1.5
    rubyonrails rails 3.1.5 rc1
    rubyonrails rails 3.1.6
    rubyonrails rails 3.1.7
    rubyonrails rails 3.1.8
    rubyonrails rails 3.1.9
    rubyonrails rails 3.1.10
    rubyonrails rails 3.2.0
    rubyonrails rails 3.2.0 rc1
    rubyonrails rails 3.2.0 rc2
    rubyonrails rails 3.2.1
    rubyonrails rails 3.2.2
    rubyonrails rails 3.2.2 rc1
    rubyonrails rails 3.2.3
    rubyonrails rails 3.2.3 rc1
    rubyonrails rails 3.2.3 rc2
    rubyonrails rails 3.2.4
    rubyonrails rails 3.2.4 rc1
    rubyonrails rails 3.2.5
    rubyonrails rails 3.2.6
    rubyonrails rails 3.2.7
    rubyonrails rails 3.2.8
    rubyonrails rails 3.2.9
    rubyonrails rails 3.2.10
    rubyonrails rails 3.2.11
    rubyonrails rails 3.2.12
    rubyonrails rails 3.2.13
    rubyonrails rails 3.2.13 rc1
    rubyonrails rails 3.2.13 rc2
    rubyonrails rails 3.2.15
    rubyonrails rails 3.2.15 rc3
    rubyonrails ruby on rails 3.0.4
    rubyonrails ruby on rails 3.2.14
    rubyonrails ruby on rails 3.2.14 rc1
    rubyonrails ruby on rails 3.2.14 rc2
    rubyonrails ruby on rails 3.2.15 rc1
    rubyonrails ruby on rails 3.2.15 rc2
    rubyonrails ruby on rails *
    rubyonrails ruby on rails 3.2.16
    rubyonrails ruby on rails 4.0.2
    puppetlabs puppet 3.1.0