Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-0263

Опубликовано: 08 фев. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 5.1

Описание

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

РелизСтатусПримечание
devel

released

1.5.2-1
esm-apps/xenial

released

1.5.2-1
esm-infra-legacy/trusty

released

1.5.2-1
hardy

DNE

lucid

DNE

oneiric

DNE

precise

ignored

end of life
precise/esm

DNE

precise was needed
quantal

ignored

end of life
raring

ignored

end of life

Показывать по

EPSS

Процентиль: 90%
0.05283
Низкий

5.1 Medium

CVSS2

Связанные уязвимости

redhat
почти 13 лет назад

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

nvd
почти 13 лет назад

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

debian
почти 13 лет назад

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, ...

github
почти 4 года назад

Rack arbitrary code execution via timing attack

EPSS

Процентиль: 90%
0.05283
Низкий

5.1 Medium

CVSS2