CVE Vulnerabilities

CVE-2013-0277

Published: Feb 13, 2013 | Modified: Aug 08, 2019
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
7.5 CRITICAL
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V3
Ubuntu
MEDIUM

ActiveRecord in Ruby on Rails before 2.3.17 and 3.x before 3.1.0 allows remote attackers to cause a denial of service or execute arbitrary code via crafted serialized attributes that cause the +serialize+ helper to deserialize arbitrary YAML.

Affected Software

Name Vendor Start Version End Version
Rails Rubyonrails 3.0.0 (including) 3.0.0 (including)
Rails Rubyonrails 3.0.0-beta (including) 3.0.0-beta (including)
Rails Rubyonrails 3.0.0-beta2 (including) 3.0.0-beta2 (including)
Rails Rubyonrails 3.0.0-beta3 (including) 3.0.0-beta3 (including)
Rails Rubyonrails 3.0.0-beta4 (including) 3.0.0-beta4 (including)
Rails Rubyonrails 3.0.0-rc (including) 3.0.0-rc (including)
Rails Rubyonrails 3.0.0-rc2 (including) 3.0.0-rc2 (including)
Rails Rubyonrails 3.0.1 (including) 3.0.1 (including)
Rails Rubyonrails 3.0.1-pre (including) 3.0.1-pre (including)
Rails Rubyonrails 3.0.2 (including) 3.0.2 (including)
Rails Rubyonrails 3.0.2-pre (including) 3.0.2-pre (including)
Rails Rubyonrails 3.0.3 (including) 3.0.3 (including)
Rails Rubyonrails 3.0.4-rc1 (including) 3.0.4-rc1 (including)
Rails Rubyonrails 3.0.5 (including) 3.0.5 (including)
Rails Rubyonrails 3.0.5-rc1 (including) 3.0.5-rc1 (including)
Rails Rubyonrails 3.0.6 (including) 3.0.6 (including)
Rails Rubyonrails 3.0.6-rc1 (including) 3.0.6-rc1 (including)
Rails Rubyonrails 3.0.6-rc2 (including) 3.0.6-rc2 (including)
Rails Rubyonrails 3.0.7 (including) 3.0.7 (including)
Rails Rubyonrails 3.0.7-rc1 (including) 3.0.7-rc1 (including)
Rails Rubyonrails 3.0.7-rc2 (including) 3.0.7-rc2 (including)
Rails Rubyonrails 3.0.8 (including) 3.0.8 (including)
Rails Rubyonrails 3.0.8-rc1 (including) 3.0.8-rc1 (including)
Rails Rubyonrails 3.0.8-rc2 (including) 3.0.8-rc2 (including)
Rails Rubyonrails 3.0.8-rc3 (including) 3.0.8-rc3 (including)
Rails Rubyonrails 3.0.8-rc4 (including) 3.0.8-rc4 (including)
Rails Rubyonrails 3.0.9 (including) 3.0.9 (including)
Rails Rubyonrails 3.0.9-rc1 (including) 3.0.9-rc1 (including)
Rails Rubyonrails 3.0.9-rc2 (including) 3.0.9-rc2 (including)
Rails Rubyonrails 3.0.9-rc3 (including) 3.0.9-rc3 (including)
Rails Rubyonrails 3.0.9-rc4 (including) 3.0.9-rc4 (including)
Rails Rubyonrails 3.0.9-rc5 (including) 3.0.9-rc5 (including)
Rails Rubyonrails 3.0.10 (including) 3.0.10 (including)
Rails Rubyonrails 3.0.10-rc1 (including) 3.0.10-rc1 (including)
Rails Rubyonrails 3.0.11 (including) 3.0.11 (including)
Rails Rubyonrails 3.0.12 (including) 3.0.12 (including)
Rails Rubyonrails 3.0.12-rc1 (including) 3.0.12-rc1 (including)
Rails Rubyonrails 3.0.13 (including) 3.0.13 (including)
Rails Rubyonrails 3.0.13-rc1 (including) 3.0.13-rc1 (including)
Rails Rubyonrails 3.0.14 (including) 3.0.14 (including)
Rails Rubyonrails 3.0.16 (including) 3.0.16 (including)
Rails Rubyonrails 3.0.17 (including) 3.0.17 (including)
Rails Rubyonrails 3.0.18 (including) 3.0.18 (including)
Rails Rubyonrails 3.0.19 (including) 3.0.19 (including)
Rails Rubyonrails 3.0.20 (including) 3.0.20 (including)
Ruby_on_rails Rubyonrails 3.0.4 (including) 3.0.4 (including)
Rails Ubuntu hardy *
Rails Ubuntu lucid *
Rails Ubuntu upstream *
Ruby-activerecord-2.3 Ubuntu oneiric *
Ruby-activerecord-2.3 Ubuntu precise *
Ruby-activerecord-2.3 Ubuntu quantal *
Ruby-activerecord-2.3 Ubuntu raring *
Ruby-activerecord-2.3 Ubuntu saucy *
Ruby-activerecord-2.3 Ubuntu upstream *

References