Upstream information
Description
CRLF injection vulnerability in Ruby on Rails before 2.0.5 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL to the redirect_to function.Novell/SUSE information
Novell Bugzilla entry: 436934, 447441 SUSE Security Advisories:- SUSE-SR:2008:027, published Tue, 09 Dec 2008 15:00:00 +0000
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| openSUSE 10.2 |
| |
| openSUSE 10.3 |
| |
| SLE SDK 10 SP1 for IBM iSeries and IBM pSeries SLE SDK 10 SP1 for IBM zSeries SLE SDK 10 SP1 for IPF SLE SDK 10 SP1 for X86-64 SLE SDK 10 SP1 for x86 |
| sle10-sp1-sdk.ia64 sle10-sp2-sdk.x86 sle10-sp1-sdk.x86 sle10-sp2-sdk.ia64 sle10-sp1-sdk.s390x sle10-sp2-sdk.ppc sle10-sp2-sdk.s390x sle10-sp1-sdk.ppc sle10-sp1-sdk.x86-64 sle10-sp2-sdk.x86-64 ZYPP Patch Nr: 5821 |
