CVE-2013-0155
SUSE Cloud 1.0,SUSE Lifecycle Management Server 1.3,SUSE Linux Enterprise High Availability Extension 11 SP3,SUSE Linux Enterprise Software Development Kit 11 SP2,SUSE Studio Extension for System z 1.2,SUSE Studio Onsite 1.2 [Appliance - Studio],SUSE Studio Onsite 1.3,SUSE Studio Standard Edition 1.2,WebYaST 1.2,WebYaST 1.3
CVE-2013-0155, security advisory, novell, suse linux, suse, security, cve

CVE-2013-0155

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-0155 at MITRE

Description

Ruby on Rails 3.0.x before 3.0.19, 3.1.x before 3.1.10, and 3.2.x before 3.2.11 does not properly consider differences in parameter handling between the Active Record component and the JSON implementation, which allows remote attackers to bypass intended database-query restrictions and perform NULL checks or trigger missing WHERE clauses via a crafted request, as demonstrated by certain "[nil]" values, a related issue to CVE-2012-2660 and CVE-2012-2694.

SUSE information

CVSS v2 Scores
  National Vulnerability Database
Base Score 6.42
Vector AV:N/AC:L/Au:N/C:P/I:P/A:N
Access Vector Network
Access Complexity Low
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact None
SUSE Bugzilla entries: 797449 [RESOLVED / FIXED], 846239 [RESOLVED / FIXED], 853625 [RESOLVED / FIXED], 853627 [RESOLVED / FIXED], 854786 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Linux Enterprise Software Development Kit 11 SP2
  • rubygem-actionmailer-2_3 >= 2.3.17-0.9.1
  • rubygem-actionpack-2_3 >= 2.3.17-0.9.1
  • rubygem-activerecord-2_3 >= 2.3.17-0.9.1
  • rubygem-activeresource-2_3 >= 2.3.17-0.9.1
  • rubygem-activesupport-2_3 >= 2.3.17-0.9.1
  • rubygem-rails >= 2.3.17-0.8.1
  • rubygem-rails-2_3 >= 2.3.17-0.9.1
Patchnames:
sdksp2-rubygem-actionmailer-2_3
SUSE Studio Onsite Runner 1.2
  • rubygem-actionmailer-2_3 >= 2.3.17-0.6.1
  • rubygem-actionpack-2_3 >= 2.3.17-0.6.1
  • rubygem-activerecord-2_3 >= 2.3.17-0.6.1
  • rubygem-activeresource-2_3 >= 2.3.17-0.6.1
  • rubygem-activesupport-2_3 >= 2.3.17-0.6.1
  • rubygem-rails-2_3 >= 2.3.17-0.6.2
Patchnames:
slestso12-rubygem-actionmailer-2_3
SUSE Cloud 1.0
  • rubygem-actionmailer-2_3 >= 2.3.17-0.9.1
  • rubygem-actionpack-2_3 >= 2.3.17-0.9.1
  • rubygem-activerecord-2_3 >= 2.3.17-0.9.1
  • rubygem-activeresource-2_3 >= 2.3.17-0.9.1
  • rubygem-activesupport-2_3 >= 2.3.17-0.9.1
  • rubygem-rails-2_3 >= 2.3.17-0.9.1
Builds
SAT Patch Nr: 7363
SUSE Linux Enterprise Software Development Kit 11 SP2
  • rubygem-actionmailer-2_3 >= 2.3.17-0.9.1
  • rubygem-actionpack-2_3 >= 2.3.17-0.9.1
  • rubygem-activerecord-2_3 >= 2.3.17-0.9.1
  • rubygem-activeresource-2_3 >= 2.3.17-0.9.1
  • rubygem-activesupport-2_3 >= 2.3.17-0.9.1
  • rubygem-rails >= 2.3.16-0.7.1
  • rubygem-rails-2_3 >= 2.3.17-0.9.1
Builds
SAT Patch Nr: 7363
SUSE Linux Enterprise High Availability Extension 11 SP3
  • hawk >= 0.6.1-0.17.1
  • hawk-templates >= 0.6.1-0.17.1
Builds
SAT Patch Nr: 9208
SUSE Lifecycle Management Server 1.3
SUSE Studio Onsite 1.3
WebYaST 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
Builds
SAT Patch Nr: 8667
SUSE Studio Standard Edition 1.2
  • rubygem-actionmailer-2_3 >= 2.3.17-0.6.1
  • rubygem-actionpack-2_3 >= 2.3.17-0.6.1
  • rubygem-activerecord-2_3 >= 2.3.17-0.6.1
  • rubygem-activeresource-2_3 >= 2.3.17-0.6.1
  • rubygem-activesupport-2_3 >= 2.3.17-0.6.1
  • rubygem-rails >= 2.3.16-0.4.5.1
  • rubygem-rails-2_3 >= 2.3.17-0.6.1
Builds
SAT Patch Nr: 7364
SUSE Studio Extension for System z 1.2
SUSE Studio Onsite 1.2 [Appliance - Studio]
WebYaST 1.2
  • rubygem-actionmailer-2_3 >= 2.3.17-0.6.1
  • rubygem-actionpack-2_3 >= 2.3.17-0.6.1
  • rubygem-activerecord-2_3 >= 2.3.17-0.6.1
  • rubygem-activeresource-2_3 >= 2.3.17-0.6.1
  • rubygem-activesupport-2_3 >= 2.3.17-0.6.1
  • rubygem-rails-2_3 >= 2.3.17-0.6.1
Builds
SAT Patch Nr: 7364
SUSE Cloud 1.0
  • rubygem-merb-core >= 1.1.3-0.9.1
Builds
SAT Patch Nr: 7405
openSUSE 12.3
  • rubygem-actionpack-3_2 >= 3.2.12-1.8.1
  • rubygem-actionpack-3_2-doc >= 3.2.12-1.8.1
Patchnames:
openSUSE-2013-989
openSUSE 13.1
  • rubygem-actionpack-3_2 >= 3.2.13-2.4.1
  • rubygem-actionpack-3_2-doc >= 3.2.13-2.4.1
Patchnames:
openSUSE-2013-990
openSUSE Evergreen 11.4
  • rubygem-actionmailer >= 2.3.16-0.6.1
  • rubygem-actionmailer-2_3 >= 2.3.16-0.16.1
  • rubygem-actionmailer-2_3-doc >= 2.3.16-0.16.1
  • rubygem-actionmailer-2_3-testsuite >= 2.3.16-0.16.1
  • rubygem-actionpack >= 2.3.16-0.6.1
  • rubygem-actionpack-2_3 >= 2.3.16-0.23.1
  • rubygem-actionpack-2_3-doc >= 2.3.16-0.23.1
  • rubygem-actionpack-2_3-testsuite >= 2.3.16-0.23.1
  • rubygem-activerecord >= 2.3.16-0.6.1
  • rubygem-activerecord-2_3 >= 2.3.16-0.19.1
  • rubygem-activerecord-2_3-doc >= 2.3.16-0.19.1
  • rubygem-activerecord-2_3-testsuite >= 2.3.16-0.19.1
  • rubygem-activeresource >= 2.3.16-0.6.1
  • rubygem-activeresource-2_3 >= 2.3.16-0.16.1
  • rubygem-activeresource-2_3-doc >= 2.3.16-0.16.1
  • rubygem-activeresource-2_3-testsuite >= 2.3.16-0.16.1
  • rubygem-activesupport >= 2.3.16-0.6.1
  • rubygem-activesupport-2_3 >= 2.3.16-0.16.1
  • rubygem-activesupport-2_3-doc >= 2.3.16-0.16.1
  • rubygem-rack >= 1.1.5-0.8.1
  • rubygem-rails >= 2.3.16-0.6.1
  • rubygem-rails-2_3 >= 2.3.16-0.12.1
  • rubygem-rails-2_3-doc >= 2.3.16-0.12.1
Patchnames:
2013-21