Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

Debian DSA-2620-1 Critical: Remote Code Execution in Rails

debian
Calendar Grey February 12, 2013
Debian Logo
Several security flaws in Ruby on Rails may result in unauthorized code execution or specific application issues. It is recommended to update immediately.
Two vulnerabilities were discovered in Ruby on Rails, a Ruby framework for web application development

Summary

Two vulnerabilities were discovered in Ruby on Rails, a Ruby framework
for web application development.

CVE-2013-0276
The blacklist provided by the attr_protected method could be
bypassed with crafted requests, having an application-specific
impact.

CVE-2013-0277
In some applications, the +serialize+ helper in ActiveRecord
could be tricked into deserializing arbitrary YAML data,
possibly leading to remote code execution.

For the stable distribution (squeeze), these problems have been fixed
in version 2.3.5-1.2+squeeze7.

We recommend that you upgrade your rails packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: http://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: rails
CVE ID: CVE-2013-0276 CVE-2013-0277

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here