Ruby on Rails CVE-2013-0277 Remote Code Execution Vulnerability
BID:57898
Info
Ruby on Rails CVE-2013-0277 Remote Code Execution Vulnerability
| Bugtraq ID: | 57898 |
| Class: | Unknown |
| CVE: |
CVE-2013-0277 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 11 2013 12:00AM |
| Updated: | Apr 16 2015 05:44PM |
| Credit: | Tobias Kraze |
| Vulnerable: |
Ruby on Rails Ruby on Rails 3.0.13 Ruby on Rails Ruby on Rails 3.0.12 Ruby on Rails Ruby on Rails 3.0.11 Ruby on Rails Ruby on Rails 3.0.6 Ruby on Rails Ruby on Rails 3.0.5 Ruby on Rails Ruby on Rails 3.0.4 Ruby on Rails Ruby on Rails 3.0.3 Ruby on Rails Ruby on Rails 3.0.2 Ruby on Rails Ruby on Rails 2.3.11 Ruby on Rails Ruby on Rails 2.3.10 Ruby on Rails Ruby on Rails 2.3.9 Ruby on Rails Ruby on Rails 2.3.5 Ruby on Rails Ruby on Rails 2.3.4 Ruby on Rails Ruby on Rails 2.3.3 Ruby on Rails Ruby on Rails 2.3.2 Ruby on Rails Ruby on Rails 3.0.8 Ruby on Rails Ruby on Rails 3.0.7 Ruby on Rails Ruby on Rails 3.0.10 Ruby on Rails Ruby on Rails 2.3.14 Ruby on Rails Ruby on Rails 2.3.13 Ruby on Rails Ruby on Rails 2.3.12 Gentoo Linux Debian Linux 6.0 sparc Debian Linux 6.0 s/390 Debian Linux 6.0 powerpc Debian Linux 6.0 mips Debian Linux 6.0 ia-64 Debian Linux 6.0 ia-32 Debian Linux 6.0 arm Debian Linux 6.0 amd64 Apple Mac Os X Server 10.7.4 Apple Mac Os X Server 10.7.3 Apple Mac Os X Server 10.7.1 Apple Mac Os X Server 10.7 Apple Mac Os X Server 10.6.8 Apple Mac Os X 10.7.4 Apple Mac Os X 10.7.3 Apple Mac Os X 10.7.2 Apple Mac Os X 10.7.1 |
| Not Vulnerable: |
Ruby on Rails Ruby on Rails 3.1.5 Ruby on Rails Ruby on Rails 3.1.4 Ruby on Rails Ruby on Rails 3.1.2 |
Discussion
Ruby on Rails CVE-2013-0277 Remote Code Execution Vulnerability
Ruby on Rails is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Ruby on Rails is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Ruby on Rails CVE-2013-0277 Remote Code Execution Vulnerability
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Ruby on Rails CVE-2013-0277 Remote Code Execution Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Apple Mac OS X 10.8.3
Apple Mac OS X 10.8
Apple Mac OS X 10.6.8
Apple Mac OS X 10.7.5
Apple Mac OS X 10.8.2
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Apple Mac OS X 10.8.3
-
Apple OSXUpd10.8.4.dmg
For OS X Mountain Lion v10.8.3
http://www.apple.com/support/downloads/
Apple Mac OS X 10.8
-
Apple OSXUpdCombo10.8.4.dmg
For OS X Mountain Lion v10.8 and v10.8.2
http://www.apple.com/support/downloads/
Apple Mac OS X 10.6.8
-
Apple SecUpdSrvr2013-002.dmg
For Mac OS X Server v10.6.8
http://www.apple.com/support/downloads/
Apple Mac OS X 10.7.5
-
Apple SecUpd2013-002.dmg
For OS X Lion v10.7.5
http://www.apple.com/support/downloads/ -
Apple SecUpdSrvr2013-002.dmg
For OS X Lion Server v10.7.5
http://www.apple.com/support/downloads/
Apple Mac OS X 10.8.2
-
Apple OSXUpdCombo10.8.4.dmg
For OS X Mountain Lion v10.8 and v10.8.2
http://www.apple.com/support/downloads/
References
Ruby on Rails CVE-2013-0277 Remote Code Execution Vulnerability
References:
References: