CVE-2013-4389
17.10.2013, 00:55
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.Enginsight
| Vendor | Product | Version |
|---|---|---|
| rubyonrails | rails | 3.0.0 ≤ 𝑥 < 3.2.15 |
| opensuse | opensuse | 12.2 |
| opensuse | opensuse | 12.3 |
| opensuse | opensuse | 13.1 |
| debian | debian_linux | 7.0 |
𝑥
= Vulnerable software versions
Debian Releases
Ubuntu Releases
Ubuntu Product | |||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rails |
| ||||||||||||
| rails-4.0 |
| ||||||||||||
| ruby-actionmailer-2.3 |
| ||||||||||||
| ruby-actionmailer-3.2 |
| ||||||||||||
| ruby-actionpack-2.3 |
| ||||||||||||
| ruby-actionpack-3.2 |
| ||||||||||||
| ruby-activerecord-2.3 |
| ||||||||||||
| ruby-activerecord-3.2 |
| ||||||||||||
| ruby-activesupport-2.3 |
| ||||||||||||
| ruby-activesupport-3.2 |
| ||||||||||||
| ruby-rails-2.3 |
| ||||||||||||
| ruby-rails-3.2 |
|
Common Weakness Enumeration
References