CVE-2013-4389
17.10.2013, 00:55
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.Enginsight
Vendor | Product | Version |
---|---|---|
rubyonrails | rails | 3.0.0 ≤ 𝑥 < 3.2.15 |
opensuse | opensuse | 12.2 |
opensuse | opensuse | 12.3 |
opensuse | opensuse | 13.1 |
debian | debian_linux | 7.0 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Ubuntu Product | |||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|
rails |
| ||||||||||||
rails-4.0 |
| ||||||||||||
ruby-actionmailer-2.3 |
| ||||||||||||
ruby-actionmailer-3.2 |
| ||||||||||||
ruby-actionpack-2.3 |
| ||||||||||||
ruby-actionpack-3.2 |
| ||||||||||||
ruby-activerecord-2.3 |
| ||||||||||||
ruby-activerecord-3.2 |
| ||||||||||||
ruby-activesupport-2.3 |
| ||||||||||||
ruby-activesupport-3.2 |
| ||||||||||||
ruby-rails-2.3 |
| ||||||||||||
ruby-rails-3.2 |
|
Common Weakness Enumeration
References