PT-2013-4991 · Ruby+1 · Ruby On Rails+1

CVE-2013-4389

·

Publicado

2013-10-17

·

Atualizado

2023-05-19

CVSS v2.0

4.3

Média

VetorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions prior to 3.2.15
Description The issue concerns multiple format string vulnerabilities in the log subscriber.rb files within the log subscriber component of Action Mailer in Ruby on Rails. These vulnerabilities can be exploited by remote attackers who send crafted e-mail addresses, which are then improperly handled during the construction of a log message, leading to a denial of service.
Recommendations For versions prior to 3.2.15, update to version 3.2.15 or later to resolve the issue.

Exploit

Correção

DoS

Use of Externally-Controlled Format String

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2013-4389
DSA-2887-1
DSA-2888-1
GHSA-RG5M-3FQP-6PX8
SUSE-SU-2014_0137-1
SUSE-SU-2014_0686-1

Produtos afetados

Ruby On Rails
Suse