Multiple vulnerabilities, remote code execution - CVE-2013-0156

Bug #1097643 reported by Erno Kuusela
270
This bug affects 3 people
Affects Status Importance Assigned to Milestone
rails (Ubuntu)
Confirmed
Undecided
Unassigned

Bug Description

More information and patches at

https://groups.google.com/forum/#!topic/rubyonrails-security/61bkgvnSGTQ/discussion

ProblemType: Bug
DistroRelease: Ubuntu 12.04
Package: rails (not installed)
ProcVersionSignature: Ubuntu 3.2.0-34.53-generic 3.2.33
Uname: Linux 3.2.0-34-generic x86_64
ApportVersion: 2.0.1-0ubuntu15.1
Architecture: amd64
Date: Wed Jan 9 11:33:20 2013
InstallationMedia: Ubuntu 10.10 "Maverick Meerkat" - Release amd64 (20101007)
MarkForUpload: True
ProcEnviron:
 LANGUAGE=en_US:en
 TERM=xterm
 PATH=(custom, no user)
 LANG=en_US.UTF-8
 SHELL=/bin/bash
SourcePackage: rails
UpgradeStatus: Upgraded to precise on 2012-07-24 (168 days ago)

CVE References

Revision history for this message
Marc Deslauriers (mdeslaur) wrote :

Thanks for taking the time to report this bug and helping to make Ubuntu better. Since the package referred to in this bug is in universe or multiverse, it is community maintained. If you are able, I suggest coordinating with upstream and posting a debdiff for this issue. When a debdiff is available, members of the security team will review it and publish the package. See the following link for more information: https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures

Changed in rails (Ubuntu):
status: New → Incomplete
information type: Private Security → Public Security
Revision history for this message
Stefan Beckers privat (stefan-beckers) wrote :
Revision history for this message
bootlog (bootmaps) wrote :

See also: http://weblog.rubyonrails.org/2013/1/8/Rails-3-2-11-3-1-10-3-0-19-and-2-3-15-have-been-released/
"These releases contain two extremely critical security fixes so please update IMMEDIATELY."

bootlog (bootmaps)
Changed in rails (Ubuntu):
status: Incomplete → Confirmed
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.