Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-4389

Опубликовано: 16 окт. 2013
Источник: redhat
CVSS2: 5

Описание

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

Отчет

Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/. This issue did not affect the versions of rubygem-actionmailer as shipped with Red Hat Subscription Asset Manager 1 as they do not include support for sending email using user supplied addresses.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1ruby193-rubygem-actionmailerWill not fix
Red Hat OpenStack Platform 3ruby193-rubygem-actionmailerWill not fix
Red Hat OpenStack Platform 4ruby193-rubygem-actionmailerWill not fix
Red Hat Satellite 6ruby193-rubygem-actionmailerWill not fix
Red Hat Software Collectionsruby193-rubygem-actionmailerWill not fix
Red Hat Subscription Asset Managerruby193-rubygem-actionmailerWill not fix
Red Hat Subscription Asset Managerrubygem-actionmailerNot affected
CloudForms Management Engine 5.4cfmeFixedRHBA-2015:110016.06.2015
CloudForms Management Engine 5.4cfme-gemsetFixedRHBA-2015:110016.06.2015
CloudForms Management Engine 5.4cfme-vnc-pluginFixedRHBA-2015:110016.06.2015

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-134
https://bugzilla.redhat.com/show_bug.cgi?id=1013913rubygem-actionmailer: email address processing DoS

5 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 12 лет назад

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

nvd
больше 12 лет назад

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

debian
больше 12 лет назад

Multiple format string vulnerabilities in log_subscriber.rb files in t ...

github
больше 8 лет назад

actionmailer email address processing causes Denial of service

5 Medium

CVSS2

Уязвимость CVE-2013-4389