Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

Debian: DSA-2301-1 Critical: Rails Remote Threats and SQL Injection

debian
Calendar Grey September 5, 2011
Debian Logo
Ensure your Debian system is running the newest Rails version to address significant vulnerabilities highlighted in the DSA-2301-1 advisory.
Several vulnerabilities have been discovered in Rails, the Ruby web application framework

Summary

CVE-2009-4214

A cross-site scripting (XSS) vulnerability had been found in the
strip_tags function. An attacker may inject non-printable characters that certain browsers will then evaluate. This vulnerability only
affects the oldstable distribution (lenny).

CVE-2011-2930

A SQL injection vulnerability had been found in the quote_table_name
method could allow malicious users to inject arbitrary SQL into a
query.

CVE-2011-2931

A cross-site scripting (XSS) vulnerability had been found in the
strip_tags helper. An parsing error can be exploited by an attacker,
who can confuse the parser and may inject HTML tags into the output
document.

CVE-2011-3186

A newline (CRLF) injection vulnerability had been found in
response.rb. This vulnerability allows an attacker to inject arbitrary
HTTP headers and conduct HTTP response splitting attacks via the
Content-Type header.

For the oldstable distribution (lenny), this problem has been fixed in
version 2.1.0-7...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: rails
CVE ID: CVE-2011-2930 CVE-2011-2931 CVE-2011-3186 CVE-2009-4214

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here