actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 02:01
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.opensuse.org/opensuse-updates/2014-02/msg00081.html - | |
References | () http://openwall.com/lists/oss-security/2014/02/18/10 - | |
References | () http://rhn.redhat.com/errata/RHSA-2014-0215.html - | |
References | () http://rhn.redhat.com/errata/RHSA-2014-0306.html - | |
References | () http://secunia.com/advisories/57376 - | |
References | () http://secunia.com/advisories/57836 - | |
References | () http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/ - | |
References | () https://groups.google.com/forum/message/raw?msg=rubyonrails-security/LMxO_3_eCuc/ozGBEhKaJbIJ - | |
References | () https://puppet.com/security/cve/cve-2014-0082 - |
Information
Published : 2014-02-20 15:27
Updated : 2024-11-21 02:01
NVD link : CVE-2014-0082
Mitre link : CVE-2014-0082
CVE.ORG link : CVE-2014-0082
JSON object : View
Products Affected
rubyonrails
- rails
- ruby_on_rails
CWE
CWE-20
Improper Input Validation