Upstream information
Description
The Active Record component in Ruby on Rails before 3.0.14, 3.1.x before 3.1.6, and 3.2.x before 3.2.6 does not properly implement the passing of request data to a where method in an ActiveRecord class, which allows remote attackers to conduct certain SQL injection attacks via nested query parameters that leverage improper handling of nested hashes, a related issue to CVE-2012-2661.NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entry: 766792 SUSE Security Advisories:- SUSE-SU-2012:1011-1, published Tue, 21 Aug 2012 19:08:36 +0200 (CEST)
- SUSE-SU-2012:1012-1, published Tue, 21 Aug 2012 19:08:38 +0200 (CEST)
- SUSE-SU-2012:1014-1, published Tue, 21 Aug 2012 20:08:28 +0200 (CEST)
- SUSE-SU-2013:0508-1, published Wed, 20 Mar 2013 17:04:42 +0100 (CET)
- openSUSE-SU-2012:0978-1, published Thu, 9 Aug 2012 18:08:34 +0200 (CEST)
- openSUSE-SU-2012:1066-1, published Thu, 30 Aug 2012 12:09:43 +0200 (CEST)
- openSUSE-SU-2013:0278-1, published Tue, 12 Feb 2013 10:10:39 +0100 (CET)
- openSUSE-SU-2013:0280-1, published Tue, 12 Feb 2013 11:04:29 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.x86-64 sle11-sp2-sdk.x86 sle11-sp2-sdk.s390x sle11-sp2-sdk.ia64 sle11-sp2-sdk.ppc SAT Patch Nr: 6630 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] SUSE Studio Standard Edition 1.2 WebYaST 1.2 |
| webyast12.ia64 studioonsite1.2.s390x slms1.2.x86-64 webyast12.ppc studioonsite1.2.x86-64 webyast12.x86-64 webyast12.s390x webyast12.x86 SAT Patch Nr: 6633 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| sle11-sp2-sdk.s390x sle11-sp2-sdk.x86-64 sle11-sp2-sdk.x86 sle11-sp2-sdk.ia64 sle11-sp2-sdk.ppc SAT Patch Nr: 6632 |
| SUSE Linux Enterprise Software Development Kit 11 SP1 |
| sle11-sp1-sdk.x86 sle11-sp1-sdk.x86-64 sle11-sp1-sdk.s390x sle11-sp1-sdk.ppc sle11-sp1-sdk.ia64 SAT Patch Nr: 6620 |
| SUSE Cloud 1.0 |
| Builds SAT Patch Nr: 7405 |
