Upstream information
Description
actionpack/lib/action_dispatch/http/request.rb in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly consider differences in parameter handling between the Active Record component and the Rack interface, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks via a crafted request, as demonstrated by certain "['xyz', nil]" values, a related issue to CVE-2012-2660.NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:P/I:N/A:N)
Novell/SUSE information
Novell Bugzilla entry: 766791, 797449 SUSE Security Advisories:- SUSE-SU-2012:1012-1, published Tue, 21 Aug 2012 19:08:38 +0200 (CEST)
- SUSE-SU-2012:1014-1, published Tue, 21 Aug 2012 20:08:28 +0200 (CEST)
- SUSE-SU-2012:1015-1, published Tue, 21 Aug 2012 20:08:29 +0200 (CEST)
- openSUSE-SU-2012:0978-1, published Thu, 9 Aug 2012 18:08:34 +0200 (CEST)
- openSUSE-SU-2012:1066-1, published Thu, 30 Aug 2012 12:09:43 +0200 (CEST)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.x86-64 sle11-sp2-sdk.x86 sle11-sp2-sdk.s390x sle11-sp2-sdk.ia64 sle11-sp2-sdk.ppc SAT Patch Nr: 6630 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| webyast12.ia64 studioonsite1.2.s390x slms1.2.x86-64 webyast12.ppc studioonsite1.2.x86-64 webyast12.x86-64 webyast12.s390x webyast12.x86 SAT Patch Nr: 6633 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| webyast12.ppc webyast12.x86-64 webyast12.x86 webyast12.s390x studioonsite1.2.x86-64 slms1.2.x86-64 webyast12.ia64 studioonsite1.2.s390x SAT Patch Nr: 6665 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| Builds SAT Patch Nr: 7031 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.s390x sle11-sp2-sdk.x86-64 sle11-sp2-sdk.x86 sle11-sp2-sdk.ia64 sle11-sp2-sdk.ppc SAT Patch Nr: 6632 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sle11-sp1-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.x86-64 sle11-sp1-sdk.ia64 SAT Patch Nr: 6619 |
| SUSE Linux Enterprise High Availability Extension 11 SP2 |
| Builds SAT Patch Nr: 7078 |
| SUSE Cloud 1.0 SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 7030 |
