Upstream information
Description
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion.NVD CVSS v2 Base Score: 7.5 (AV:N/AC:L/Au:N/C:P/I:P/A:P)
Novell/SUSE information
Novell Bugzilla entries: 797452, 798321, 800320 SUSE Security Advisories:- SUSE-SU-2013:0486-1, published Tue, 19 Mar 2013 18:04:46 +0100 (CET)
- SUSE-SU-2013:0508-1, published Wed, 20 Mar 2013 17:04:42 +0100 (CET)
- SUSE-SU-2013:0606-1, published Wed, 3 Apr 2013 20:06:19 +0200 (CEST)
- openSUSE-SU-2013:0278-1, published Tue, 12 Feb 2013 10:10:39 +0100 (CET)
- openSUSE-SU-2013:0280-1, published Tue, 12 Feb 2013 11:04:29 +0100 (CET)
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Cloud 1.0 |
| Builds SAT Patch Nr: 7363 |
| SUSE Linux Enterprise Software Development Kit 11 SP2 |
| Builds SAT Patch Nr: 7363 |
| SUSE Studio Standard Edition 1.2 |
| Builds SAT Patch Nr: 7364 |
| SUSE Studio Extension for System z 1.2 SUSE Studio Onsite 1.2 [Appliance - Studio] WebYaST 1.2 |
| Builds SAT Patch Nr: 7364 |
| SUSE Cloud 1.0 |
| Builds SAT Patch Nr: 7405 |
