Novell Home

CVE-2013-4389

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-4389 at MITRE

Description

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

NVD CVSS v2 Base Score: 4.3 (AV:N/AC:M/Au:N/C:N/I:N/A:P)

Novell/SUSE information

Novell Bugzilla entry: 846239, 854786

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Software Development Kit 11 SP3
  • rubygem-activesupport-3_2 >= 3.2.12-0.7.1
Builds
SAT Patch Nr: 8670
SLE 11 SP3 DEBUGINFO
  • hawk-debuginfo >= 0.6.1-0.17.1
  • hawk-debugsource >= 0.6.1-0.17.1
Builds
SAT Patch Nr: 9208
SUSE Linux Enterprise High Availability Extension 11 SP3
  • hawk >= 0.6.1-0.17.1
  • hawk-templates >= 0.6.1-0.17.1
Builds
SAT Patch Nr: 9208
SUSE Lifecycle Management Server 1.3
SUSE Studio Onsite 1.3
WebYaST 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
Builds
SAT Patch Nr: 8667
SUSE Linux Enterprise Software Development Kit 11 SP3
  • rubygem-actionmailer-3_1 >= 3.1.4-0.7.3
Builds
SAT Patch Nr: 8664
SUSE Linux Enterprise Software Development Kit 11 SP3
  • rubygem-activesupport-3_1 >= 3.1.4-0.7.1
Builds
SAT Patch Nr: 8668
SUSE Lifecycle Management Server 1.3
SUSE Studio Onsite 1.3
WebYaST 1.3
  • rubygem-actionmailer-3_2 >= 3.2.12-0.7.3
Builds
SAT Patch Nr: 8665
SUSE Lifecycle Management Server 1.3
SUSE Linux Enterprise Software Development Kit 11 SP2
SUSE Studio Onsite 1.3
WebYaST 1.3
  • rubygem-activesupport-3_2 >= 3.2.12-0.7.1
Builds
SAT Patch Nr: 8669
SUSE Studio Onsite 1.3
  • susestudio >= 1.3.7-0.17.1
  • susestudio-admin_en >= 11.3-0.15.1
  • susestudio-admin_en-pdf >= 11.3-0.15.1
  • susestudio-bundled-packages >= 1.3.7-0.17.1
  • susestudio-common >= 1.3.7-0.17.1
  • susestudio-runner >= 1.3.7-0.17.1
  • susestudio-sid >= 1.3.7-0.17.1
  • susestudio-ui-server >= 1.3.7-0.17.1
Builds
SAT Patch Nr: 9308
SUSE Linux Enterprise Software Development Kit 11 SP3
  • rubygem-activemodel-3_1 >= 3.1.4-0.7.1
Builds
SAT Patch Nr: 8677

© 2014 Novell