#VU33108 Input validation error


Published: 2013-03-20 | Updated: 2020-08-03

Vulnerability identifier: #VU33108

Vulnerability risk: Medium

CVSSv3.1: 4.6 [CVSS:3.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C]

CVE-ID: CVE-2013-1854

CWE-ID: CWE-20

Exploitation vector: Network

Exploit availability: No

Description

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.

Mitigation
Install update from vendor's website.

External links
http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html
http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00070.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00071.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00075.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00078.html
http://lists.opensuse.org/opensuse-updates/2013-04/msg00079.html
http://rhn.redhat.com/errata/RHSA-2013-0699.html
http://rhn.redhat.com/errata/RHSA-2014-1863.html
http://support.apple.com/kb/HT5784
http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/
http://groups.google.com/group/ruby-security-ann/msg/34e0d780b04308de?dmode=source&output=gplain


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.


Latest bulletins with this vulnerability