CVE Vulnerabilities

CVE-2013-0263

Published: Feb 08, 2013 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5.1 MEDIUM
AV:N/AC:H/Au:N/C:P/I:P/A:P
RedHat/V2
5 MODERATE
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V3
Ubuntu
MEDIUM

Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.

Affected Software

Name Vendor Start Version End Version
Rack Rack_project 1.5.0 (including) 1.5.0 (including)
Rack Rack_project 1.5.1 (including) 1.5.1 (including)
Red Hat Subscription Asset Manager 1.2 RedHat candlepin-0:0.7.24-1.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-0:1.2.1.1-1h.el6_4 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-configure-0:1.2.3.1-4h.el6_4 *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-actionpack-1:3.0.10-12.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-activemodel-0:3.0.10-3.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-delayed_job-0:2.1.4-3.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-json-0:1.7.3-2.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-rack-1:1.3.0-4.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-rails_warden-0:0.5.5-2.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-rdoc-0:3.8-6.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat thumbslug-0:0.0.28.1-1.el6_4 *
RHEL 6 Version of OpenShift Enterprise RedHat jenkins-0:1.502-1.el6op *
RHEL 6 Version of OpenShift Enterprise RedHat openshift-origin-cartridge-jenkins-1.4-0:1.0.3-1.el6op *
RHEL 6 Version of OpenShift Enterprise RedHat ruby193-rubygem-rack-1:1.4.1-4.el6 *
RHEL 6 Version of OpenShift Enterprise RedHat rubygem-rack-1:1.3.0-4.el6op *
Ruby-rack Ubuntu devel *
Ruby-rack Ubuntu precise *
Ruby-rack Ubuntu quantal *
Ruby-rack Ubuntu raring *
Ruby-rack Ubuntu saucy *
Ruby-rack Ubuntu trusty *
Ruby-rack Ubuntu upstream *
Ruby-rack Ubuntu utopic *
Ruby-rack Ubuntu vivid *
Ruby-rack Ubuntu wily *
Ruby-rack Ubuntu xenial *
Ruby-rack Ubuntu yakkety *
Ruby-rack Ubuntu zesty *

References