Upstream information
Description
Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.NVD CVSS v2 Base Score: 6.4 (AV:N/AC:L/Au:N/C:P/I:P/A:N)
Novell/SUSE information
Novell Bugzilla entry: 797449 SUSE Security Advisories:- SUSE-SU-2013:0486-1, published Tue, 19 Mar 2013 18:04:46 +0100 (CET)
- SUSE-SU-2013:0508-1, published Wed, 20 Mar 2013 17:04:42 +0100 (CET)
- SUSE-SU-2013:0606-1, published Wed, 3 Apr 2013 20:06:19 +0200 (CEST)
- openSUSE-SU-2013:0278-1, published Tue, 12 Feb 2013 10:10:39 +0100 (CET)
- openSUSE-SU-2013:0280-1, published Tue, 12 Feb 2013 11:04:29 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Cloud 1.0 |
| Builds SAT Patch Nr: 7363 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 7363 |
| SUSE Studio Standard Edition 1.2 |
| Builds SAT Patch Nr: 7364 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] WebYaST 1.2 |
| Builds SAT Patch Nr: 7364 |
| SUSE Cloud 1.0 |
| Builds SAT Patch Nr: 7405 |
