CVE-2011-0447
SUSE Linux Enterprise Software Development Kit 11 SP1,SUSE Linux Enterprise Software Development Kit 11 SP2,SUSE Studio Extension for System z 1.2,SUSE Studio Onsite 1.2 [Appliance - Studio],SUSE Studio Standard Edition 1.2,WebYaST 1.2,openSUSE 11.3,openSUSE 11.4
CVE-2011-0447, security advisory, novell, suse linux, suse, security, cve

CVE-2011-0447

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2011-0447 at MITRE

Description

Ruby on Rails 2.1.x, 2.2.x, and 2.3.x before 2.3.11, and 3.x before 3.0.4, does not properly validate HTTP requests that contain an X-Requested-With header, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via forged (1) AJAX or (2) API requests that leverage "combinations of browser plugins and HTTP redirects," a related issue to CVE-2011-0696.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.82
Vector AV:N/AC:M/Au:N/C:P/I:P/A:P
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
SUSE Bugzilla entry: 668817 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Studio Onsite Runner 1.2
  • rubygem-actionmailer-2_3 >= 2.3.14-0.7.4.3
  • rubygem-actionpack-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activerecord-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activeresource-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activesupport-2_3 >= 2.3.14-0.7.4.3
  • rubygem-rack >= 1.1.2-0.8.8.3
  • rubygem-rails-2_3 >= 2.3.14-0.7.4.3
Patchnames:
slestso12-rubyonrails-2314-201202
SUSE Linux Enterprise Software Development Kit 11 SP1
SUSE Studio Standard Edition 1.2
  • rubygem-actionmailer-2_3 >= 2.3.14-0.7.4.3
  • rubygem-actionpack-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activerecord-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activeresource-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activesupport-2_3 >= 2.3.14-0.7.4.3
  • rubygem-rack >= 1.1.2-0.8.8.3
  • rubygem-rails >= 2.3.14-0.8.6.1
  • rubygem-rails-2_3 >= 2.3.14-0.7.4.3
Builds
SAT Patch Nr: 5884
SUSE Studio Extension for System z 1.2
SUSE Studio Onsite 1.2 [Appliance - Studio]
WebYaST 1.2
  • rubygem-actionmailer-2_3 >= 2.3.14-0.7.4.3
  • rubygem-actionpack-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activerecord-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activeresource-2_3 >= 2.3.14-0.7.4.3
  • rubygem-activesupport-2_3 >= 2.3.14-0.7.4.3
  • rubygem-rack >= 1.1.2-0.8.8.3
  • rubygem-rails-2_3 >= 2.3.14-0.7.4.3
Builds
SAT Patch Nr: 5884
SUSE Linux Enterprise Software Development Kit 11 SP1
SUSE Linux Enterprise Software Development Kit 11 SP2
  • rubygem-actionpack-2_1 >= 2.1.2-1.12.2
  • rubygem-activerecord-2_1 >= 2.1.2-1.4.5
sle11-sp2-sdk.ia64
sle11-sp2-sdk.s390x
sle11-sp2-sdk.x86-64
sle11-sp1-sdk.s390x
sle11-sp1-sdk.x86-64
sle11-sp1-sdk.x86
sle11-sp2-sdk.ppc
sle11-sp1-sdk.ia64
sle11-sp1-sdk.ppc
sle11-sp2-sdk.x86
SAT Patch Nr: 5875
openSUSE 11.3
  • rubygem-actionmailer >= 2.3.14-0.3.1
  • rubygem-actionmailer-2_3 >= 2.3.14-0.3.1
  • rubygem-actionpack >= 2.3.14-0.3.1
  • rubygem-actionpack-2_3 >= 2.3.14-0.2.1
  • rubygem-activerecord >= 2.3.14-0.3.1
  • rubygem-activerecord-2_3 >= 2.3.14-0.3.1
  • rubygem-activeresource >= 2.3.14-0.3.1
  • rubygem-activeresource-2_3 >= 2.3.14-0.3.1
  • rubygem-activesupport >= 2.3.14-0.3.1
  • rubygem-activesupport-2_3 >= 2.3.14-0.3.1
  • rubygem-rack >= 1.1.2-0.3.1
  • rubygem-rails >= 2.3.14-0.3.1
  • rubygem-rails-2_3 >= 2.3.14-0.3.1
openSUSE 11.4
  • rubygem-actionmailer >= 2.3.14-0.3.1
  • rubygem-actionmailer-2_3 >= 2.3.14-0.3.1
  • rubygem-actionmailer-2_3-doc >= 2.3.14-0.3.1
  • rubygem-actionmailer-2_3-testsuite >= 2.3.14-0.3.1
  • rubygem-actionpack >= 2.3.14-0.3.1
  • rubygem-actionpack-2_3 >= 2.3.14-0.3.1
  • rubygem-actionpack-2_3-doc >= 2.3.14-0.3.1
  • rubygem-actionpack-2_3-testsuite >= 2.3.14-0.3.1
  • rubygem-activerecord >= 2.3.14-0.3.1
  • rubygem-activerecord-2_3 >= 2.3.14-0.3.1
  • rubygem-activerecord-2_3-doc >= 2.3.14-0.3.1
  • rubygem-activerecord-2_3-testsuite >= 2.3.14-0.3.1
  • rubygem-activeresource >= 2.3.14-0.3.1
  • rubygem-activeresource-2_3 >= 2.3.14-0.3.1
  • rubygem-activeresource-2_3-doc >= 2.3.14-0.3.1
  • rubygem-activeresource-2_3-testsuite >= 2.3.14-0.3.1
  • rubygem-activesupport >= 2.3.14-0.3.1
  • rubygem-activesupport-2_3 >= 2.3.14-0.3.1
  • rubygem-activesupport-2_3-doc >= 2.3.14-0.3.1
  • rubygem-rack >= 1.1.2-0.3.1
  • rubygem-rails >= 2.3.14-0.3.1
  • rubygem-rails-2_3 >= 2.3.14-0.3.1
  • rubygem-rails-2_3-doc >= 2.3.14-0.3.1
openSUSE 11.4
  • rubygem-actionmailer >= 2.3.14-0.3.1
  • rubygem-actionmailer-2_3 >= 2.3.14-0.3.1
  • rubygem-actionmailer-2_3-doc >= 2.3.14-0.3.1
  • rubygem-actionmailer-2_3-testsuite >= 2.3.14-0.3.1
  • rubygem-actionpack >= 2.3.14-0.3.1
  • rubygem-actionpack-2_3 >= 2.3.14-0.3.1
  • rubygem-actionpack-2_3-doc >= 2.3.14-0.3.1
  • rubygem-actionpack-2_3-testsuite >= 2.3.14-0.3.1
  • rubygem-activerecord >= 2.3.14-0.3.1
  • rubygem-activerecord-2_3 >= 2.3.14-0.3.1
  • rubygem-activerecord-2_3-doc >= 2.3.14-0.3.1
  • rubygem-activerecord-2_3-testsuite >= 2.3.14-0.3.1
  • rubygem-activeresource >= 2.3.14-0.3.1
  • rubygem-activeresource-2_3 >= 2.3.14-0.3.1
  • rubygem-activeresource-2_3-doc >= 2.3.14-0.3.1
  • rubygem-activeresource-2_3-testsuite >= 2.3.14-0.3.1
  • rubygem-activesupport >= 2.3.14-0.3.1
  • rubygem-activesupport-2_3 >= 2.3.14-0.3.1
  • rubygem-activesupport-2_3-doc >= 2.3.14-0.3.1
  • rubygem-rack >= 1.1.2-0.3.1
  • rubygem-rails >= 2.3.14-0.3.1
  • rubygem-rails-2_3 >= 2.3.14-0.3.1
  • rubygem-rails-2_3-doc >= 2.3.14-0.3.1
Patchnames:
rubygem-actionmailer