CVE-2013-0263
Summary
| CVE | CVE-2013-0263 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2013-02-08 20:55:00 UTC |
| Updated | 2023-02-13 04:40:00 UTC |
| Description | Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rack Project | Rack | 1.1.0 | All | All | All |
| Application | Rack Project | Rack | 1.1.4 | All | All | All |
| Application | Rack Project | Rack | 1.1.5 | All | All | All |
| Application | Rack Project | Rack | 1.1.6 | All | All | All |
| Application | Rack Project | Rack | 1.2.0 | All | All | All |
| Application | Rack Project | Rack | 1.2.1 | All | All | All |
| Application | Rack Project | Rack | 1.2.2 | All | All | All |
| Application | Rack Project | Rack | 1.2.3 | All | All | All |
| Application | Rack Project | Rack | 1.2.4 | All | All | All |
| Application | Rack Project | Rack | 1.2.6 | All | All | All |
| Application | Rack Project | Rack | 1.2.7 | All | All | All |
| Application | Rack Project | Rack | 1.3.0 | All | All | All |
| Application | Rack Project | Rack | 1.3.1 | All | All | All |
| Application | Rack Project | Rack | 1.3.2 | All | All | All |
| Application | Rack Project | Rack | 1.3.3 | All | All | All |
| Application | Rack Project | Rack | 1.3.4 | All | All | All |
| Application | Rack Project | Rack | 1.3.5 | All | All | All |
| Application | Rack Project | Rack | 1.3.6 | All | All | All |
| Application | Rack Project | Rack | 1.3.7 | All | All | All |
| Application | Rack Project | Rack | 1.3.8 | All | All | All |
| Application | Rack Project | Rack | 1.3.9 | All | All | All |
| Application | Rack Project | Rack | 1.4.0 | All | All | All |
| Application | Rack Project | Rack | 1.4.1 | All | All | All |
| Application | Rack Project | Rack | 1.4.2 | All | All | All |
| Application | Rack Project | Rack | 1.4.3 | All | All | All |
| Application | Rack Project | Rack | 1.4.4 | All | All | All |
| Application | Rack Project | Rack | 1.5.0 | All | All | All |
| Application | Rack Project | Rack | 1.5.1 | All | All | All |
| Application | Rack Project | Rack | 1.1.0 | All | All | All |
| Application | Rack Project | Rack | 1.1.4 | All | All | All |
| Application | Rack Project | Rack | 1.1.5 | All | All | All |
| Application | Rack Project | Rack | 1.1.6 | All | All | All |
| Application | Rack Project | Rack | 1.2.0 | All | All | All |
| Application | Rack Project | Rack | 1.2.1 | All | All | All |
| Application | Rack Project | Rack | 1.2.2 | All | All | All |
| Application | Rack Project | Rack | 1.2.3 | All | All | All |
| Application | Rack Project | Rack | 1.2.4 | All | All | All |
| Application | Rack Project | Rack | 1.2.6 | All | All | All |
| Application | Rack Project | Rack | 1.2.7 | All | All | All |
| Application | Rack Project | Rack | 1.3.0 | All | All | All |
| Application | Rack Project | Rack | 1.3.1 | All | All | All |
| Application | Rack Project | Rack | 1.3.2 | All | All | All |
| Application | Rack Project | Rack | 1.3.3 | All | All | All |
| Application | Rack Project | Rack | 1.3.4 | All | All | All |
| Application | Rack Project | Rack | 1.3.5 | All | All | All |
| Application | Rack Project | Rack | 1.3.6 | All | All | All |
| Application | Rack Project | Rack | 1.3.7 | All | All | All |
| Application | Rack Project | Rack | 1.3.8 | All | All | All |
| Application | Rack Project | Rack | 1.3.9 | All | All | All |
| Application | Rack Project | Rack | 1.4.0 | All | All | All |
| Application | Rack Project | Rack | 1.4.1 | All | All | All |
| Application | Rack Project | Rack | 1.4.2 | All | All | All |
| Application | Rack Project | Rack | 1.4.3 | All | All | All |
| Application | Rack Project | Rack | 1.4.4 | All | All | All |
| Application | Rack Project | Rack | 1.5.0 | All | All | All |
| Application | Rack Project | Rack | 1.5.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Use secure_compare for hmac comparison · rack/rack@0cd7e9a · GitHub | CONFIRM | github.com | |
| Omelas County Chamber of Commerce na Twitterze: "Rack just released a fix for CVE-2013-0263, a timing attack vulnerability I reported to them TWO AND A HALF YEARS AGO BACK WHEN IT WAS COOL." | MISC | twitter.com | |
| Google Groups | CONFIRM | groups.google.com | |
| Add secure_compare to Rack::Utils · rack/rack@9a81b96 · GitHub | CONFIRM | github.com | |
| Rack: a Ruby Webserver Interface | CONFIRM | rack.github.com | Vendor Advisory |
| CVE-2013-0263 | Puppet | CONFIRM | puppet.com | |
| Redirecting to Google Groups | MISC | groups.google.com | |
| openSUSE-SU-2013:0462-1: moderate: RubyOnRails: security version update | SUSE | lists.opensuse.org | |
| Google Groups | CONFIRM | groups.google.com | |
| Debian -- Security Information -- DSA-2783-1 librack-ruby | DEBIAN | www.debian.org | |
| Google Groups | CONFIRM | groups.google.com | |
| Security Advisory SA52033 - Rack Insecure File Access Security Issue - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| Security Advisory SA52774 - Red Hat update for Red Hat Subscription Asset Manager - Secunia | SECUNIA | secunia.com | |
| 89939 | OSVDB | www.osvdb.org | |
| Red Hat Customer Portal | REDHAT | rhn.redhat.com | |
| Google Groups | CONFIRM | groups.google.com | |
| Redirecting to Google Groups | MISC | groups.google.com | |
| gist:f9f3781f7b54985bee94 · GitHub | MISC | gist.github.com | |
| Google Groups | CONFIRM | groups.google.com | |
| Security Advisory SA52134 - Rack "Rack::Session::Cookie" Information Disclosure Security Issue - Secunia | SECUNIA | secunia.com | Vendor Advisory |
| 909071 – (CVE-2013-0263) CVE-2013-0263 rubygem-rack: Timing attack in cookie sessions | MISC | bugzilla.redhat.com | |
| Redirecting to Google Groups | MISC | groups.google.com | |
| Redirecting to Google Groups | MISC | groups.google.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.