PT-2013-4991 · Ruby+1 · Ruby On Rails+1

Published

2013-10-17

·

Updated

2023-05-19

·

CVE-2013-4389

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Ruby on Rails versions prior to 3.2.15
Description The issue concerns multiple format string vulnerabilities in the log subscriber.rb files within the log subscriber component of Action Mailer in Ruby on Rails. These vulnerabilities can be exploited by remote attackers who send crafted e-mail addresses, which are then improperly handled during the construction of a log message, leading to a denial of service.
Recommendations For versions prior to 3.2.15, update to version 3.2.15 or later to resolve the issue.

Exploit

Fix

DoS

Use of Externally-Controlled Format String

Weakness Enumeration

Related Identifiers

CVE-2013-4389
DSA-2887-1
DSA-2888-1
GHSA-RG5M-3FQP-6PX8
SUSE-SU-2014_0137-1
SUSE-SU-2014_0686-1

Affected Products

Ruby On Rails
Suse