Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

Debian 2.3.5-1.2-5 Critical: Rails SQL Manipulation Risk

debian
Calendar Grey January 16, 2013
Debian Logo
The latest Debian advisory DSA-2609-1 highlights a critical security patch for Rails aimed at mitigating risks associated with SQL query injection and unauthorized privilege escalation.
An interpretation conflict can cause the Active Record component of Rails, a web framework for the Ruby programming language, to truncate queries in unexpected ways

Summary

An interpretation conflict can cause the Active Record component of
Rails, a web framework for the Ruby programming language, to truncate
queries in unexpected ways. This may allow attackers to elevate their
privileges.

For the stable distribution (squeeze), this problem has been fixed in
version 2.3.5-1.2+squeeze5.

We recommend that you upgrade your rails packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: rails
CVE ID: CVE-2013-0155

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here