Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-2604-1 Critical: Rails Insufficient Input Validation

debian
Calendar Grey January 9, 2013
Debian Logo
Uncover the Debian security patch DSA-2604-1 for the Rails framework that tackles input validation vulnerabilities and possible exploitations.
It was discovered that Rails, the Ruby web application development framework, performed insufficient validation on input parameters, allowing unintended type conversions

Summary

For the stable distribution (squeeze), this problem has been fixed in
version 2.3.5-1.2+squeeze4.1.

For the testing distribution (wheezy) and unstable distribution (sid),
this problem will be fixed soon.

We recommend that you upgrade your rails packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: rails
CVE ID: CVE-2013-0156

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here