CVE-2013-4389
Publication date 17 October 2013
Last updated 24 July 2024
Ubuntu priority
Description
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| rails | 14.04 LTS trusty | Not in release |
| rails-4.0 | 14.04 LTS trusty | Not in release |
| ruby-actionmailer-2.3 | 14.04 LTS trusty | Not in release |
| ruby-actionmailer-3.2 | 14.04 LTS trusty | Not in release |
| ruby-actionpack-2.3 | 14.04 LTS trusty | Not in release |
| ruby-actionpack-3.2 | 14.04 LTS trusty | Not in release |
| ruby-activerecord-2.3 | 14.04 LTS trusty | Not in release |
| ruby-activerecord-3.2 | 14.04 LTS trusty | Not in release |
| ruby-activesupport-2.3 | 14.04 LTS trusty | Not in release |
| ruby-activesupport-3.2 | 14.04 LTS trusty | Not in release |
| ruby-rails-2.3 | 14.04 LTS trusty | Not in release |
| ruby-rails-3.2 | 14.04 LTS trusty | Not in release |
Notes
mdeslaur
in Oneiric+, rails package is just for transition
seth-arnold
Only 3.x.x is affected; earlier and 4.0.x are safe The patch standardizes some log handling across multiple packages, but the security fix looks restricted to just one line in action mailer: info("\nSent mail to #{recipients} ... the other packages can be left alone.
Patch details
| Package | Patch details |
|---|---|
| ruby-actionmailer-3.2 |