ID

VAR-201303-0426


CVE

CVE-2013-1857


TITLE

Ruby on Rails of Action Pack Cross-site scripting vulnerability in component

Trust: 0.8

sources: JVNDB: JVNDB-2013-001930

DESCRIPTION

The sanitize helper in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle encoded : (colon) characters in URLs, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via a crafted scheme name, as demonstrated by including a &#x3a; sequence. An attacker may leverage this issue to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This may allow the attacker to steal cookie-based authentication credentials and to launch other attacks. Affected packages ================= ------------------------------------------------------------------- Package / Vulnerable / Unaffected ------------------------------------------------------------------- 1 dev-ruby/rails < 2.3.18 >= 2.3.18 * ------------------------------------------------------------------- NOTE: Packages marked with asterisks require manual intervention! Description =========== Multiple vulnerabilities have been discovered in Ruby on Rails. Please review the CVE identifiers referenced below for details. Furthermore, a remote attacker may be able to execute arbitrary SQL commands, change parameter names for form inputs and make changes to arbitrary records in the system, bypass intended access restrictions, render arbitrary views, inject arbitrary web script or HTML, or conduct cross-site request forgery (CSRF) attacks. Workaround ========== There is no known workaround at this time. Resolution ========== All Ruby on Rails 2.x users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=dev-ruby/rails-2.3.18" NOTE: All applications using Ruby on Rails should also be configured to use the latest version available by running "rake rails:update" inside the application directory. NOTE: This is a legacy GLSA and stable updates for Ruby on Rails, including the unaffected version listed above, are no longer available from Gentoo. It may be possible to upgrade to the 3.2, 4.0, or 4.1 branches, however these packages are not currently stable. References ========== [ 1 ] CVE-2010-3933 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-3933 [ 2 ] CVE-2011-0446 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0446 [ 3 ] CVE-2011-0447 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0447 [ 4 ] CVE-2011-0448 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0448 [ 5 ] CVE-2011-0449 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-0449 [ 6 ] CVE-2011-2929 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2929 [ 7 ] CVE-2011-2930 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2930 [ 8 ] CVE-2011-2931 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2931 [ 9 ] CVE-2011-2932 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-2932 [ 10 ] CVE-2011-3186 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2011-3186 [ 11 ] CVE-2013-0155 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0155 [ 12 ] CVE-2013-0156 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0156 [ 13 ] CVE-2013-0276 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0276 [ 14 ] CVE-2013-0277 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0277 [ 15 ] CVE-2013-0333 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-0333 [ 16 ] CVE-2013-1854 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1854 [ 17 ] CVE-2013-1855 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1855 [ 18 ] CVE-2013-1856 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1856 [ 19 ] CVE-2013-1857 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-1857 Availability ============ This GLSA and any updates to it are available for viewing at the Gentoo Security Website: http://security.gentoo.org/glsa/glsa-201412-28.xml Concerns? ========= Security is a primary focus of Gentoo Linux and ensuring the confidentiality and security of our users' machines is of utmost importance to us. Any security concerns should be addressed to security@gentoo.org or alternatively, you may file a bug at https://bugs.gentoo.org. License ======= Copyright 2014 Gentoo Foundation, Inc; referenced text belongs to its owner(s). The contents of this document are licensed under the Creative Commons - Attribution / Share Alike license. http://creativecommons.org/licenses/by-sa/2.5 . For the stable distribution (squeeze), these problems have been fixed in version 2.3.5-1.2+squeeze8. For the testing distribution (wheezy) and the unstable distribution (sid), these problems have been fixed in the version 3.2.6-5 of ruby-activerecord-3.2, version 2.3.14-6 of ruby-activerecord-2.3, version 2.3.14-7 of ruby-activesupport-2.3, version 3.2.6-6 of ruby-actionpack-3.2 and in version 2.3.14-5 of ruby-actionpack-2.3. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 APPLE-SA-2013-06-04-1 OS X Mountain Lion v10.8.4 and Security Update 2013-002 OS X Mountain Lion v10.8.4 and Security Update 2013-002 is now available and addresses the following: CFNetwork Available for: OS X Mountain Lion v10.8 to v10.8.3 Impact: An attacker with access to a user's session may be able to log into previously accessed sites, even if Private Browsing was used Description: Permanent cookies were saved after quitting Safari, even when Private Browsing was enabled. This issue was addressed by improved handling of cookies. CVE-ID CVE-2013-0982 : Alexander Traud of www.traud.de CoreAnimation Available for: OS X Mountain Lion v10.8 to v10.8.3 Impact: Visiting a maliciously crafted site may lead to an unexpected application termination or arbitrary code execution Description: An unbounded stack allocation issue existed in the handling of text glyphs. This could be triggered by maliciously crafted URLs in Safari. The issue was addressed through improved bounds checking. CVE-ID CVE-2013-0983 : David Fifield of Stanford University, Ben Syverson CoreMedia Playback Available for: OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.3 Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution Description: An uninitialized memory access issue existed in the handling of text tracks. This issue was addressed by additional validation of text tracks. CVE-ID CVE-2013-1024 : Richard Kuo and Billy Suguitan of Triemt Corporation CUPS Available for: OS X Mountain Lion v10.8 to v10.8.3 Impact: A local user in the lpadmin group may be able to read or write arbitrary files with system privileges Description: A privilege escalation issue existed in the handling of CUPS configuration via the CUPS web interface. A local user in the lpadmin group may be able to read or write arbitrary files with system privileges. This issue was addressed by moving certain configuration directives to cups-files.conf, which can not be modified from the CUPS web interface. CVE-ID CVE-2012-5519 Directory Service Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8 Impact: A remote attacker may execute arbitrary code with system privileges on systems with Directory Service enabled Description: An issue existed in the directory server's handling of messages from the network. This issue was addressed through improved bounds checking. This issue does not affect OS X Lion or OS X Mountain Lion systems. CVE-ID CVE-2013-0984 : Nicolas Economou of Core Security Disk Management Available for: OS X Mountain Lion v10.8 to v10.8.3 Impact: A local user may disable FileVault Description: A local user who is not an administrator may disable FileVault using the command-line. This issue was addressed by adding additional authentication. CVE-ID CVE-2013-0985 OpenSSL Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.3 Impact: An attacker may be able to decrypt data protected by SSL Description: There were known attacks on the confidentiality of TLS 1.0 when compression was enabled. This issue was addressed by disabling compression in OpenSSL. CVE-ID CVE-2012-4929 : Juliano Rizzo and Thai Duong OpenSSL Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.3 Impact: Multiple vulnerabilities in OpenSSL Description: OpenSSL was updated to version 0.9.8x to address multiple vulnerabilities, which may lead to denial of service or disclosure of a private key. Further information is available via the OpenSSL website at http://www.openssl.org/news/ CVE-ID CVE-2011-1945 CVE-2011-3207 CVE-2011-3210 CVE-2011-4108 CVE-2011-4109 CVE-2011-4576 CVE-2011-4577 CVE-2011-4619 CVE-2012-0050 CVE-2012-2110 CVE-2012-2131 CVE-2012-2333 QuickDraw Manager Available for: OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.2 Impact: Opening a maliciously crafted PICT image may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in the handling of PICT images. This issue was addressed through improved bounds checking. CVE-ID CVE-2013-0975 : Tobias Klein working with HP's Zero Day Initiative QuickTime Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.3 Impact: Viewing a maliciously crafted movie file may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in the handling of 'enof' atoms. This issue was addressed through improved bounds checking. CVE-ID CVE-2013-0986 : Tom Gallagher (Microsoft) & Paul Bates (Microsoft) working with HP's Zero Day Initiative QuickTime Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.3 Impact: Viewing a maliciously crafted QTIF file may lead to an unexpected application termination or arbitrary code execution Description: A memory corruption issue existed in the handling of QTIF files. This issue was addressed through improved bounds checking. CVE-ID CVE-2013-0987 : roob working with iDefense VCP QuickTime Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8, OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.3 Impact: Viewing a maliciously crafted FPX file may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in the handling of FPX files. This issue was addressed through improved bounds checking. CVE-ID CVE-2013-0988 : G. Geshev working with HP's Zero Day Initiative QuickTime Available for: OS X Mountain Lion v10.8 to v10.8.3 Impact: Playing a maliciously crafted MP3 file may lead to an unexpected application termination or arbitrary code execution Description: A buffer overflow existed in the handling of MP3 files. This issue was addressed through improved bounds checking. CVE-ID CVE-2013-0989 : G. Geshev working with HP's Zero Day Initiative Ruby Available for: Mac OS X 10.6.8, Mac OS X Server 10.6.8 Impact: Multiple vulnerabilities in Ruby on Rails Description: Multiple vulnerabilities existed in Ruby on Rails, the most serious of which may lead to arbitrary code execution on systems running Ruby on Rails applications. These issues were addressed by updating Ruby on Rails to version 2.3.18. This issue may affect OS X Lion or OS X Mountain Lion systems that were upgraded from Mac OS X 10.6.8 or earlier. Users can update affected gems on such systems by using the /usr/bin/gem utility. CVE-ID CVE-2013-0155 CVE-2013-0276 CVE-2013-0277 CVE-2013-0333 CVE-2013-1854 CVE-2013-1855 CVE-2013-1856 CVE-2013-1857 SMB Available for: OS X Lion v10.7 to v10.7.5, OS X Lion Server v10.7 to v10.7.5, OS X Mountain Lion v10.8 to v10.8.3 Impact: An authenticated user may be able to write files outside the shared directory Description: If SMB file sharing is enabled, an authenticated user may be able to write files outside the shared directory. This issue was addressed through improved access control. CVE-ID CVE-2013-0990 : Ward van Wanrooij Note: Starting with OS X 10.8.4, Java Web Start (i.e. JNLP) applications downloaded from the Internet need to be signed with a Developer ID certificate. Gatekeeper will check downloaded Java Web Start applications for a signature and block such applications from launching if they are not properly signed. Note: OS X Mountain Lion v10.8.4 includes the content of Safari 6.0.5. For further details see "About the security content of Safari 6.0.5" at http://http//support.apple.com/kb/HT5785 OS X Mountain Lion v10.8.4 and Security Update 2013-002 may be obtained from the Software Update pane in System Preferences, or Apple's Software Downloads web site: http://www.apple.com/support/downloads/ The Software Update utility will present the update that applies to your system configuration. Only one is needed, either OS X Mountain Lion v10.8.4, or Security Update 2013-002. For OS X Mountain Lion v10.8.3 The download file is named: OSXUpd10.8.4.dmg Its SHA-1 digest is: 9cf99aa1293cefdac0fb9a24ea133c80f8237b5e For OS X Mountain Lion v10.8 and v10.8.2 The download file is named: OSXUpdCombo10.8.4.dmg Its SHA-1 digest is: 3c95d0c8d0c7f43339a5f4e137e386dd5fe409c3 For OS X Lion v10.7.5 The download file is named: SecUpd2013-002.dmg Its SHA-1 digest is: cfc3bd0941d7c5838aee9e92ee087d78abff3ce7 For OS X Lion Server v10.7.5 The download file is named: SecUpdSrvr2013-002.dmg Its SHA-1 digest is: 34dff575a145e13404e7a2ee8a390d3e7c56fb5e For Mac OS X v10.6.8 The download file is named: SecUpd2013-002.dmg Its SHA-1 digest is: 5da54b38ffb8c147925c3018a8f5bf30ad4ac5b1 For Mac OS X Server v10.6.8 The download file is named: SecUpdSrvr2013-002.dmg Its SHA-1 digest is: b20271f019930fe894c2247a6d5e05f00568b583 Information will also be posted to the Apple Security Updates web site: http://support.apple.com/kb/HT1222 This message is signed with Apple's Product Security PGP key, and details are available at: https://www.apple.com/support/security/pgp/ -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.17 (Darwin) Comment: GPGTools - http://gpgtools.org iQIcBAEBAgAGBQJRrjkiAAoJEPefwLHPlZEwW+AP/0x/cHS3VPY0/a98Xpmdfkdb eo9Ns5FKw6mIkUftrN6qwNAgFXWqQXNIbJ3q8ZnoxcFPakhYyPSp4XowpR79l7kG B2ZrdTx9aIn2bfHZ+h4cE8XnVL8qUDz2RxFopOGbb+wpJxl8/fehDmWokC5wCeF5 N7mnwW2s37QL73BmAMRdi6CYcJCKwhZWGFWmqiNvpFlUP+kcjU/UM1MAzOu0xsiA PD6NrWeUOWfFrcQgx/pspWGvrFyV4FLu+0wQBl9f/DiQNrwVXIr85rHtah+b1NCU pteSxQwb4kRojXdPm4+I3LKoghzGR8xD6+Xl6KdYgReSW89Di4bKM3WpbRLqhRuq 8kv38Gk3/vZDfAnuNQX09dE6EgJ0DVu86SoRQZ1iYRQoLrizVsOvyVQUojZhT47t 6l44L/5cNJd7EcaC8hdmr44cCZdMPDEqoKzn2BavH62WYXbZMPlHBDo/H2ujUUec i7XU7LA1Upw57X4wmIUU4QrlBhNBh39yRKh3katAklayFBjOMEyyL57gURvd6O77 gFOQpUQ6kgqwgQCrtNT6R96igfyu7cVxYW7XchZDHgA3n/YWOAVvXkVeeQ5OUGzC O0UYLMBpPka31yfWP23QaXpV+LW462raI6LnMvRP1245RhokTTThZw6/9xochK2V +VoeoamqaQqZGyOiObbU =vG2v -----END PGP SIGNATURE----- . -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ===================================================================== Red Hat Security Advisory Synopsis: Important: Subscription Asset Manager 1.4 security update Advisory ID: RHSA-2014:1863-01 Product: Red Hat Subscription Asset Manager Advisory URL: https://rhn.redhat.com/errata/RHSA-2014-1863.html Issue date: 2014-11-17 CVE Names: CVE-2013-1854 CVE-2013-1855 CVE-2013-1857 CVE-2013-4491 CVE-2013-6414 CVE-2013-6415 CVE-2014-0130 ===================================================================== 1. Summary: Updated Subscription Asset Manager 1.4 packages that fix multiple security issues are now available. Red Hat Product Security has rated this update as having Important security impact. Common Vulnerability Scoring System (CVSS) base scores, which give detailed severity ratings, are available for each vulnerability from the CVE links in the References section. 2. Relevant releases/architectures: Red Hat Subscription Asset Manager for RHEL 6 Server - noarch 3. Description: Red Hat Subscription Asset Manager acts as a proxy for handling subscription information and software updates on client machines. Red Hat Subscription Asset Manager is built on Ruby on Rails, a model-view-controller (MVC) framework for web application development. Action Pack implements the controller and the view components. A directory traversal flaw was found in the way Ruby on Rails handled wildcard segments in routes with implicit rendering. A remote attacker could use this flaw to retrieve arbitrary local files accessible to a Ruby on Rails application using the aforementioned routes via a specially crafted request. (CVE-2014-0130) A flaw was found in the way Ruby on Rails handled hashes in certain queries. A remote attacker could use this flaw to perform a denial of service (resource consumption) attack by sending specially crafted queries that would result in the creation of Ruby symbols, which were never garbage collected. (CVE-2013-1854) Two cross-site scripting (XSS) flaws were found in Action Pack. A remote attacker could use these flaws to conduct XSS attacks against users of an application using Action Pack. (CVE-2013-1855, CVE-2013-1857) It was discovered that the internationalization component of Ruby on Rails could, under certain circumstances, return a fallback HTML string that contained user input. A remote attacker could possibly use this flaw to perform a reflective cross-site scripting (XSS) attack by providing a specially crafted input to an application using the aforementioned component. (CVE-2013-4491) A denial of service flaw was found in the header handling component of Action View. A remote attacker could send strings in specially crafted headers that would be cached indefinitely, which would result in all available system memory eventually being consumed. (CVE-2013-6414) It was found that the number_to_currency Action View helper did not properly escape the unit parameter. An attacker could use this flaw to perform a cross-site scripting (XSS) attack on an application that uses data submitted by a user in the unit parameter. Upstream acknowledges Ben Murphy as the original reporter of CVE-2013-1854, Charlie Somerville as the original reporter of CVE-2013-1855, Alan Jenkins as the original reporter of CVE-2013-1857, Peter McLarnan as the original reporter of CVE-2013-4491, Toby Hsieh as the original reporter of CVE-2013-6414, and Ankit Gupta as the original reporter of CVE-2013-6415. All Subscription Asset Manager users are advised to upgrade to these updated packages, which contain backported patches to correct these issues. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. This update is available via the Red Hat Network. Details on how to use the Red Hat Network to apply this update are available at https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 921329 - CVE-2013-1854 rubygem-activerecord: attribute_dos Symbol DoS vulnerability 921331 - CVE-2013-1855 rubygem-actionpack: css_sanitization: XSS vulnerability in sanitize_css 921335 - CVE-2013-1857 rubygem-actionpack: sanitize_protocol: XSS Vulnerability in the helper of Ruby on Rails 1036483 - CVE-2013-6414 rubygem-actionpack: Action View DoS 1036910 - CVE-2013-6415 rubygem-actionpack: number_to_currency XSS 1036922 - CVE-2013-4491 rubygem-actionpack: i18n missing translation XSS 1095105 - CVE-2014-0130 rubygem-actionpack: directory traversal issue 6. Package List: Red Hat Subscription Asset Manager for RHEL 6 Server: Source: katello-1.4.3.28-1.el6sam_splice.src.rpm ruby193-rubygem-actionmailer-3.2.17-1.el6sam.src.rpm ruby193-rubygem-actionpack-3.2.17-6.el6sam.src.rpm ruby193-rubygem-activemodel-3.2.17-1.el6sam.src.rpm ruby193-rubygem-activerecord-3.2.17-5.el6sam.src.rpm ruby193-rubygem-activeresource-3.2.17-1.el6sam.src.rpm ruby193-rubygem-activesupport-3.2.17-2.el6sam.src.rpm ruby193-rubygem-i18n-0.6.9-1.el6sam.src.rpm ruby193-rubygem-mail-2.5.4-1.el6sam.src.rpm ruby193-rubygem-rack-1.4.5-3.el6sam.src.rpm ruby193-rubygem-rails-3.2.17-1.el6sam.src.rpm ruby193-rubygem-railties-3.2.17-1.el6sam.src.rpm noarch: katello-common-1.4.3.28-1.el6sam_splice.noarch.rpm katello-glue-candlepin-1.4.3.28-1.el6sam_splice.noarch.rpm katello-glue-elasticsearch-1.4.3.28-1.el6sam_splice.noarch.rpm katello-headpin-1.4.3.28-1.el6sam_splice.noarch.rpm katello-headpin-all-1.4.3.28-1.el6sam_splice.noarch.rpm ruby193-rubygem-actionmailer-3.2.17-1.el6sam.noarch.rpm ruby193-rubygem-actionpack-3.2.17-6.el6sam.noarch.rpm ruby193-rubygem-activemodel-3.2.17-1.el6sam.noarch.rpm ruby193-rubygem-activerecord-3.2.17-5.el6sam.noarch.rpm ruby193-rubygem-activeresource-3.2.17-1.el6sam.noarch.rpm ruby193-rubygem-activesupport-3.2.17-2.el6sam.noarch.rpm ruby193-rubygem-i18n-0.6.9-1.el6sam.noarch.rpm ruby193-rubygem-mail-2.5.4-1.el6sam.noarch.rpm ruby193-rubygem-rack-1.4.5-3.el6sam.noarch.rpm ruby193-rubygem-rails-3.2.17-1.el6sam.noarch.rpm ruby193-rubygem-railties-3.2.17-1.el6sam.noarch.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2013-1854 https://access.redhat.com/security/cve/CVE-2013-1855 https://access.redhat.com/security/cve/CVE-2013-1857 https://access.redhat.com/security/cve/CVE-2013-4491 https://access.redhat.com/security/cve/CVE-2013-6414 https://access.redhat.com/security/cve/CVE-2013-6415 https://access.redhat.com/security/cve/CVE-2014-0130 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is <secalert@redhat.com>. More contact details at https://access.redhat.com/security/team/contact/ Copyright 2014 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iD8DBQFUai7iXlSAg2UNWIIRAmtEAJ9m+ZUXuva81fLz9G1CLKYi5aJoHACfcd3y SoVal0zNgx0pwtSAkS1q5/0= =i5aK -----END PGP SIGNATURE----- -- RHSA-announce mailing list RHSA-announce@redhat.com https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 2.34

sources: NVD: CVE-2013-1857 // JVNDB: JVNDB-2013-001930 // BID: 58555 // PACKETSTORM: 129552 // PACKETSTORM: 121005 // PACKETSTORM: 121919 // PACKETSTORM: 121052 // PACKETSTORM: 129131

AFFECTED PRODUCTS

vendor:rubyonrailsmodel:railsscope:eqversion:0.9.4.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.2.5

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.8

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.7

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.1.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.6

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.13.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.7

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.1.6

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.1.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.3

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.1.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.10

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.12

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.13

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:lteversion:2.3.17

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.8

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.9.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.11.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.19

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.8.5

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:3.1.11

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.3

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.6

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.9

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.5.5

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.16

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.5

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.11.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.12.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.14.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.14

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.8

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.13

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.1.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.14.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.2.3

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.1.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.1.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.2.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.12

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.12.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.9.5

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.5.7

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.5.6

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.9.3

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.2.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.17

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.18

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:3.0.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.1.3

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.5.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.2.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.9.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.2.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.1.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.0.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.2.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.2.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.10.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.0.1

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.6.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.10.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.13.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.5

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.1.5

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.1

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.10

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.0.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.9

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.9.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.14.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.9

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.10

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:0.14.3

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.9

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.6

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.2.6

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.12

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.5

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.6.5

Trust: 1.0

vendor:redhatmodel:enterprise linuxscope:eqversion:6.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.10

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.3

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.11

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.16

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.7

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.0.2

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.0

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.8.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.14

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.3

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.20

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:1.2.4

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.2.11

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.0.11

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.7.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.3.15

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:2.0.0

Trust: 1.0

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:0.9.0

Trust: 1.0

vendor:rubyonrailsmodel:railsscope:eqversion:3.1.4

Trust: 1.0

vendor:ruby on railsmodel:railsscope:ltversion:3.1.x

Trust: 0.8

vendor:applemodel:mac os xscope:eqversion:10.6.8

Trust: 0.8

vendor:applemodel:macos serverscope:eqversion:3.0

Trust: 0.8

vendor:ruby on railsmodel:railsscope:eqversion:3.0.x

Trust: 0.8

vendor:ruby on railsmodel:railsscope:eqversion:3.2.13

Trust: 0.8

vendor:ruby on railsmodel:railsscope:eqversion:3.1.12

Trust: 0.8

vendor:ruby on railsmodel:railsscope:ltversion:3.2.x

Trust: 0.8

vendor:applemodel:mac os x serverscope:eqversion:10.6.8

Trust: 0.8

vendor:applemodel:macos serverscope:ltversion:(apple mac os x v10.9 or later )

Trust: 0.8

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:1.1.5

Trust: 0.6

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:1.1.6

Trust: 0.6

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:3.1.0

Trust: 0.6

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:2.0.0

Trust: 0.6

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:1.1.3

Trust: 0.6

vendor:rubyonrailsmodel:ruby on railsscope:eqversion:2.0.1

Trust: 0.6

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2.12

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2.11

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2.10

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2.8

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2.7

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2.6

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2.4

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2.2

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1.11

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1.9

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1.8

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1.7

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1.6

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1.5

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1.4

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1.2

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.1

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.17

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.16

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.15

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.11

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.10

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.9

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.5

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.4

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.3

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.2

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:3.2

Trust: 0.3

vendor:rubymodel:on rails ruby on rails 3.1.0.rc6scope: - version: -

Trust: 0.3

vendor:rubymodel:on rails ruby on rails 3.1.0.rc5scope: - version: -

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.14

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.13

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:eqversion:2.3.12

Trust: 0.3

vendor:redhatmodel:openshift enterprisescope:eqversion:1.1.3

Trust: 0.3

vendor:ibmmodel:security network protection xgsscope:eqversion:50005.0

Trust: 0.3

vendor:gentoomodel:linuxscope: - version: -

Trust: 0.3

vendor:debianmodel:linux sparcscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux s/390scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux powerpcscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux mipsscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux ia-64scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux ia-32scope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux armscope:eqversion:6.0

Trust: 0.3

vendor:debianmodel:linux amd64scope:eqversion:6.0

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.7.5

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x2.2.2

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x2.2.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x2.1.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x2.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x2.0

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.7.4

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.7.3

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.7.1

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.7

Trust: 0.3

vendor:applemodel:mac os serverscope:eqversion:x10.6.8

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.8.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.8.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.5

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.8.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.8

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.4

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.3

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.2

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7.1

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.7

Trust: 0.3

vendor:applemodel:mac osscope:eqversion:x10.6.8

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:neversion:3.2.13

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:neversion:3.1.12

Trust: 0.3

vendor:rubymodel:on rails ruby on railsscope:neversion:2.3.18

Trust: 0.3

vendor:ibmmodel:security network protection xgsscope:neversion:50005.1

Trust: 0.3

vendor:applemodel:mac os serverscope:neversion:x3.0

Trust: 0.3

vendor:applemodel:mac osscope:neversion:x10.8.4

Trust: 0.3

sources: BID: 58555 // JVNDB: JVNDB-2013-001930 // CNNVD: CNNVD-201303-391 // NVD: CVE-2013-1857

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1857
value: MEDIUM

Trust: 1.0

NVD: CVE-2013-1857
value: MEDIUM

Trust: 0.8

CNNVD: CNNVD-201303-391
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2013-1857
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

sources: JVNDB: JVNDB-2013-001930 // CNNVD: CNNVD-201303-391 // NVD: CVE-2013-1857

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.8

sources: JVNDB: JVNDB-2013-001930 // NVD: CVE-2013-1857

THREAT TYPE

remote

Trust: 0.7

sources: PACKETSTORM: 121052 // CNNVD: CNNVD-201303-391

TYPE

xss

Trust: 0.7

sources: PACKETSTORM: 121052 // CNNVD: CNNVD-201303-391

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-001930

PATCH

title:APPLE-SA-2013-06-04-1url:http://lists.apple.com/archives/security-announce/2013/Jun/msg00000.html

Trust: 0.8

title:APPLE-SA-2013-10-22-5url:http://lists.apple.com/archives/security-announce/2013/Oct/msg00006.html

Trust: 0.8

title:HT5999url:http://support.apple.com/kb/HT5999

Trust: 0.8

title:HT5784url:http://support.apple.com/kb/HT5784

Trust: 0.8

title:HT5784url:http://support.apple.com/kb/HT5784?viewlocale=ja_JP

Trust: 0.8

title:HT5999url:http://support.apple.com/kb/HT5999?viewlocale=ja_JP

Trust: 0.8

title:CVE-2013-1857 XSS Vulnerability in the sanitize helper of Ruby on Railsurl:https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/zAAU7vGTPvI

Trust: 0.8

title:openSUSE-SU-2013:0661url:http://lists.opensuse.org/opensuse-updates/2013-04/msg00072.html

Trust: 0.8

title:openSUSE-SU-2013:0662url:http://lists.opensuse.org/opensuse-updates/2013-04/msg00073.html

Trust: 0.8

title:[SEC] [ANN] Rails 3.2.13, 3.1.12, and 2.3.18 have been released!url:http://weblog.rubyonrails.org/2013/3/18/SEC-ANN-Rails-3-2-13-3-1-12-and-2-3-18-have-been-released/

Trust: 0.8

title:RHSA-2013:0698url:http://rhn.redhat.com/errata/RHSA-2013-0698.html

Trust: 0.8

title:RHSA-2014:1863url:https://rhn.redhat.com/errata/RHSA-2014-1863.html

Trust: 0.8

sources: JVNDB: JVNDB-2013-001930

EXTERNAL IDS

db:NVDid:CVE-2013-1857

Trust: 3.2

db:JVNid:JVNVU95174988

Trust: 0.8

db:JVNid:JVNVU92046435

Trust: 0.8

db:JVNDBid:JVNDB-2013-001930

Trust: 0.8

db:CNNVDid:CNNVD-201303-391

Trust: 0.6

db:BIDid:58555

Trust: 0.3

db:PACKETSTORMid:129552

Trust: 0.1

db:PACKETSTORMid:121005

Trust: 0.1

db:PACKETSTORMid:121919

Trust: 0.1

db:PACKETSTORMid:121052

Trust: 0.1

db:PACKETSTORMid:129131

Trust: 0.1

sources: BID: 58555 // JVNDB: JVNDB-2013-001930 // PACKETSTORM: 129552 // PACKETSTORM: 121005 // PACKETSTORM: 121919 // PACKETSTORM: 121052 // PACKETSTORM: 129131 // CNNVD: CNNVD-201303-391 // NVD: CVE-2013-1857

REFERENCES

url:http://rhn.redhat.com/errata/rhsa-2013-0698.html

Trust: 2.0

url:http://support.apple.com/kb/ht5784

Trust: 1.9

url:http://rhn.redhat.com/errata/rhsa-2014-1863.html

Trust: 1.7

url:http://lists.opensuse.org/opensuse-updates/2014-01/msg00013.html

Trust: 1.6

url:http://lists.opensuse.org/opensuse-updates/2013-04/msg00073.html

Trust: 1.6

url:http://lists.opensuse.org/opensuse-updates/2013-04/msg00072.html

Trust: 1.6

url:http://lists.apple.com/archives/security-announce/2013/jun/msg00000.html

Trust: 1.6

url:http://weblog.rubyonrails.org/2013/3/18/sec-ann-rails-3-2-13-3-1-12-and-2-3-18-have-been-released/

Trust: 1.6

url:https://groups.google.com/group/rubyonrails-security/msg/78b9817a5943f6d6?dmode=source&output=gplain

Trust: 1.6

url:http://lists.apple.com/archives/security-announce/2013/oct/msg00006.html

Trust: 1.6

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1857

Trust: 0.8

url:http://jvn.jp/cert/jvnvu92046435/index.html

Trust: 0.8

url:http://jvn.jp/cert/jvnvu95174988/

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1857

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2013-1857

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2013-1855

Trust: 0.5

url:https://nvd.nist.gov/vuln/detail/cve-2013-1854

Trust: 0.4

url:https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/zaau7vgtpvi

Trust: 0.3

url:https://bugzilla.redhat.com/show_bug.cgi?id=921335

Trust: 0.3

url:http://www.rubyonrails.com/

Trust: 0.3

url:http://www-01.ibm.com/support/docview.wss?uid=swg21646819

Trust: 0.3

url:https://nvd.nist.gov/vuln/detail/cve-2013-0155

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2011-2932

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-0276

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-0333

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-1856

Trust: 0.2

url:https://nvd.nist.gov/vuln/detail/cve-2013-0277

Trust: 0.2

url:https://www.redhat.com/mailman/listinfo/rhsa-announce

Trust: 0.2

url:https://access.redhat.com/security/team/contact/

Trust: 0.2

url:http://bugzilla.redhat.com/):

Trust: 0.2

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2930

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0446

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0447

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0448

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2010-3933

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2929

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0276

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0333

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1856

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1857

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0156

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2930

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0156

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2931

Trust: 0.1

url:http://creativecommons.org/licenses/by-sa/2.5

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2932

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0446

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0449

Trust: 0.1

url:http://security.gentoo.org/

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-3186

Trust: 0.1

url:http://security.gentoo.org/glsa/glsa-201412-28.xml

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-2931

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-2929

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1855

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-0449

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0448

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2011-3186

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2011-0447

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2010-3933

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0155

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-0277

Trust: 0.1

url:https://bugs.gentoo.org.

Trust: 0.1

url:http://nvd.nist.gov/nvd.cfm?cvename=cve-2013-1854

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3464

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-3465

Trust: 0.1

url:http://www.debian.org/security/faq

Trust: 0.1

url:http://www.debian.org/security/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-4929

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2333

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-1024

Trust: 0.1

url:http://support.apple.com/kb/ht1222

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0984

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0988

Trust: 0.1

url:http://www.apple.com/support/downloads/

Trust: 0.1

url:https://www.traud.de

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-5519

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0989

Trust: 0.1

url:http://www.openssl.org/news/

Trust: 0.1

url:https://www.apple.com/support/security/pgp/

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2012-2131

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0982

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0986

Trust: 0.1

url:http://gpgtools.org

Trust: 0.1

url:http://http//support.apple.com/kb/ht5785

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0987

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0990

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0975

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0985

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-0983

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2013-1857.html

Trust: 0.1

url:https://access.redhat.com/security/team/key/#package

Trust: 0.1

url:https://www.redhat.com/security/data/cve/cve-2013-1855.html

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#moderate

Trust: 0.1

url:https://access.redhat.com/knowledge/articles/11258

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2013-1855

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2013-1857

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-6415

Trust: 0.1

url:https://access.redhat.com/security/updates/classification/#important

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2013-4491

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-6414

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2013-4491

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2013-1854

Trust: 0.1

url:https://access.redhat.com/articles/11258

Trust: 0.1

url:https://nvd.nist.gov/vuln/detail/cve-2014-0130

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2014-0130

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2013-6415

Trust: 0.1

url:https://access.redhat.com/security/team/key/

Trust: 0.1

url:https://access.redhat.com/security/cve/cve-2013-6414

Trust: 0.1

sources: BID: 58555 // JVNDB: JVNDB-2013-001930 // PACKETSTORM: 129552 // PACKETSTORM: 121005 // PACKETSTORM: 121919 // PACKETSTORM: 121052 // PACKETSTORM: 129131 // CNNVD: CNNVD-201303-391 // NVD: CVE-2013-1857

CREDITS

Alan Jenkins

Trust: 0.3

sources: BID: 58555

SOURCES

db:BIDid:58555
db:JVNDBid:JVNDB-2013-001930
db:PACKETSTORMid:129552
db:PACKETSTORMid:121005
db:PACKETSTORMid:121919
db:PACKETSTORMid:121052
db:PACKETSTORMid:129131
db:CNNVDid:CNNVD-201303-391
db:NVDid:CVE-2013-1857

LAST UPDATE DATE

2024-11-23T20:54:10.300000+00:00


SOURCES UPDATE DATE

db:BIDid:58555date:2015-04-13T21:55:00
db:JVNDBid:JVNDB-2013-001930date:2014-12-18T00:00:00
db:CNNVDid:CNNVD-201303-391date:2019-04-23T00:00:00
db:NVDid:CVE-2013-1857date:2024-11-21T01:50:31.973

SOURCES RELEASE DATE

db:BIDid:58555date:2013-03-18T00:00:00
db:JVNDBid:JVNDB-2013-001930date:2013-03-22T00:00:00
db:PACKETSTORMid:129552date:2014-12-15T20:00:42
db:PACKETSTORMid:121005date:2013-03-29T01:47:56
db:PACKETSTORMid:121919date:2013-06-06T14:44:44
db:PACKETSTORMid:121052date:2013-04-02T14:44:00
db:PACKETSTORMid:129131date:2014-11-17T23:30:56
db:CNNVDid:CNNVD-201303-391date:2013-03-20T00:00:00
db:NVDid:CVE-2013-1857date:2013-03-19T22:55:01.087