Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1800

Опубликовано: 09 апр. 2013
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 7.5

Описание

The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

РелизСтатусПримечание
bionic

not-affected

0.4.3-2
devel

not-affected

esm-apps-legacy/xenial

not-affected

0.4.3-1
esm-apps/bionic

not-affected

0.4.3-2
esm-apps/focal

not-affected

esm-apps/xenial

not-affected

0.4.3-1
esm-infra-legacy/trusty

DNE

focal

not-affected

groovy

not-affected

precise/esm

DNE

Показывать по

Ссылки на источники

EPSS

Процентиль: 91%
0.04952
Низкий

7.5 High

CVSS2

Связанные уязвимости

redhat
больше 13 лет назад

The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

nvd
больше 13 лет назад

The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

debian
больше 13 лет назад

The crack gem 0.3.1 and earlier for Ruby does not properly restrict ca ...

github
почти 9 лет назад

crack does not properly restrict casts of string values

EPSS

Процентиль: 91%
0.04952
Низкий

7.5 High

CVSS2

Уязвимость CVE-2013-1800