Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2013-1800

Опубликовано: 09 апр. 2013
Источник: ubuntu
Приоритет: medium
CVSS2: 7.5

Описание

The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

РелизСтатусПримечание
bionic

not-affected

0.4.3-2
devel

not-affected

esm-apps/bionic

not-affected

0.4.3-2
esm-apps/focal

not-affected

esm-apps/xenial

not-affected

0.4.3-1
esm-infra-legacy/trusty

DNE

focal

not-affected

groovy

not-affected

precise/esm

DNE

trusty

ignored

end of standard support

Показывать по

Ссылки на источники

7.5 High

CVSS2

Связанные уязвимости

redhat
около 13 лет назад

The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

nvd
почти 13 лет назад

The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.

debian
почти 13 лет назад

The crack gem 0.3.1 and earlier for Ruby does not properly restrict ca ...

github
больше 8 лет назад

crack does not properly restrict casts of string values

7.5 High

CVSS2