CVE-2013-6415

Common Vulnerabilities and Exposures

[Previous] [Index] [Next]

Upstream information

CVE-2013-6415 at MITRE

Description

Cross-site scripting (XSS) vulnerability in the number_to_currency helper in actionpack/lib/action_view/helpers/number_helper.rb in Ruby on Rails before 3.2.16 and 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via the unit parameter.
CVSS v2 Scores
  National Vulnerability Database
Base Score 4.30
Vector AV:N/AC:M/Au:N/C:N/I:P/A:N
Access Vector Network
Access Complexity Medium
Authentication None
Confidentiality Impact None
Integrity Impact Partial
Availability Impact None

SUSE information

SUSE Bugzilla entries: 846239 [RESOLVED / FIXED], 853625 [RESOLVED / FIXED], 853632 [RESOLVED / FIXED], 854786 [RESOLVED / FIXED]

SUSE Security Advisories:

List of released packages

Product(s) Fixed package version(s) References
SUSE Lifecycle Management Server 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
Patchnames:
sleslms13-rubygem-actionpack-3_2
SUSE Linux Enterprise High Availability Extension 11 SP3
  • hawk >= 0.6.1-0.17.1
  • hawk-templates >= 0.6.1-0.17.1
Patchnames:
slehasp3-hawk
SUSE Linux Enterprise Software Development Kit 11 SP2
  • rubygem-actionpack-2_1 >= 2.1.2-1.14.1
  • rubygem-actionpack-2_3 >= 2.3.17-0.13.2
Patchnames:
sdksp2-rubygem-actionpack-2_1
sdksp2-rubygem-actionpack-2_3
SUSE Linux Enterprise Software Development Kit 11 SP3
  • rubygem-actionpack-2_1 >= 2.1.2-1.14.1
  • rubygem-actionpack-2_3 >= 2.3.17-0.13.1
Patchnames:
sdksp3-rubygem-actionpack-2_1
sdksp3-rubygem-actionpack-2_3
SUSE OpenStack Cloud 2.0
  • rubygem-actionpack-2_3 >= 2.3.17-0.13.1
Patchnames:
sleclo20sp3-rubygem-actionpack-2_3
SUSE Studio Onsite 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
  • susestudio >= 1.3.7-0.17.1
  • susestudio-admin_en >= 11.3-0.15.1
  • susestudio-admin_en-pdf >= 11.3-0.15.1
  • susestudio-bundled-packages >= 1.3.7-0.17.1
  • susestudio-common >= 1.3.7-0.17.1
  • susestudio-runner >= 1.3.7-0.17.1
  • susestudio-sid >= 1.3.7-0.17.1
  • susestudio-ui-server >= 1.3.7-0.17.1
Patchnames:
slestso13-rubygem-actionpack-3_2
slestso13-susestudio-137-201404
SUSE WebYast 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
Patchnames:
slewyst13-rubygem-actionpack-3_2
SUSE Cloud 2.0
SUSE Linux Enterprise Software Development Kit 11 SP3
  • rubygem-actionpack-2_3 >= 2.3.17-0.13.1
Builds
SAT Patch Nr: 8698
SUSE Linux Enterprise High Availability Extension 11 SP3
  • hawk >= 0.6.1-0.17.1
  • hawk-templates >= 0.6.1-0.17.1
Builds
SAT Patch Nr: 9208
SUSE Lifecycle Management Server 1.3
SUSE Studio Onsite 1.3
WebYaST 1.3
  • rubygem-actionpack-3_2 >= 3.2.12-0.11.1
Builds
SAT Patch Nr: 8667
SUSE Linux Enterprise Software Development Kit 11 SP3
  • rubygem-actionpack-2_1 >= 2.1.2-1.14.1
Builds
SAT Patch Nr: 8637
SUSE Studio Onsite 1.3
  • susestudio >= 1.3.7-0.17.1
  • susestudio-admin_en >= 11.3-0.15.1
  • susestudio-admin_en-pdf >= 11.3-0.15.1
  • susestudio-bundled-packages >= 1.3.7-0.17.1
  • susestudio-common >= 1.3.7-0.17.1
  • susestudio-runner >= 1.3.7-0.17.1
  • susestudio-sid >= 1.3.7-0.17.1
  • susestudio-ui-server >= 1.3.7-0.17.1
Builds
SAT Patch Nr: 9308
SUSE Linux Enterprise Software Development Kit 11 SP2
  • rubygem-actionpack-2_1 >= 2.1.2-1.14.1
Builds
SAT Patch Nr: 8636
SUSE Linux Enterprise Software Development Kit 11 SP2
  • rubygem-actionpack-2_3 >= 2.3.17-0.13.2
Builds
SAT Patch Nr: 8702
openSUSE 12.3
  • rubygem-actionpack-3_2 >= 3.2.12-1.13.1
  • rubygem-actionpack-3_2-doc >= 3.2.12-1.13.1
Patchnames:
openSUSE-2013-989
openSUSE-2014-1
openSUSE 13.1
  • rubygem-actionpack-3_2 >= 3.2.13-2.9.1
  • rubygem-actionpack-3_2-doc >= 3.2.13-2.9.1
Patchnames:
openSUSE-2013-990
openSUSE-2014-1
openSUSE Evergreen 11.4
  • rubygem-actionpack-2_3 >= 2.3.17-39.1
  • rubygem-actionpack-2_3-doc >= 2.3.17-39.1
  • rubygem-actionpack-2_3-testsuite >= 2.3.17-39.1
Patchnames:
2014-3