Upstream information
Description
The Active Record component in Ruby on Rails 3.0.x before 3.0.13, 3.1.x before 3.1.5, and 3.2.x before 3.2.4 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage unintended recursion, a related issue to CVE-2012-2695.NVD CVSS v2 Base Score: 5.0 (AV:N/AC:L/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry: 765074, 766792 SUSE Security Advisories:- SUSE-SU-2012:1012-1, published Tue, 21 Aug 2012 19:08:38 +0200 (CEST)
- SUSE-SU-2012:1014-1, published Tue, 21 Aug 2012 20:08:28 +0200 (CEST)
- openSUSE-SU-2012:1066-1, published Thu, 30 Aug 2012 12:09:43 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.x86-64 sle11-sp2-sdk.x86 sle11-sp2-sdk.s390x sle11-sp2-sdk.ia64 sle11-sp2-sdk.ppc SAT Patch Nr: 6630 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| webyast12.ia64 studioonsite1.2.s390x slms1.2.x86-64 webyast12.ppc studioonsite1.2.x86-64 webyast12.x86-64 webyast12.s390x webyast12.x86 SAT Patch Nr: 6633 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| webyast12.ppc webyast12.x86-64 webyast12.x86 webyast12.s390x studioonsite1.2.x86-64 slms1.2.x86-64 webyast12.ia64 studioonsite1.2.s390x SAT Patch Nr: 6665 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.s390x sle11-sp2-sdk.x86-64 sle11-sp2-sdk.x86 sle11-sp2-sdk.ia64 sle11-sp2-sdk.ppc SAT Patch Nr: 6632 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sle11-sp1-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.x86-64 sle11-sp1-sdk.ia64 SAT Patch Nr: 6619 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.ia64 SAT Patch Nr: 6620 |
