CVE Vulnerabilities

CVE-2013-4389

Use of Externally-Controlled Format String

Published: Oct 17, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
5 LOW
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

Weakness

The product uses a function that accepts a format string as an argument, but the format string originates from an external source.

Affected Software

NameVendorStart VersionEnd Version
RailsRubyonrails3.0.0 (including)3.2.15 (excluding)
CloudForms Management Engine 5.4RedHatcfme-0:5.4.0.5-1.el6cf*
CloudForms Management Engine 5.4RedHatcfme-gemset-0:5.4.0.5-1.el6cf*
CloudForms Management Engine 5.4RedHatcfme-vnc-plugin-0:1.0.0-2.el6cf*
CloudForms Management Engine 5.4RedHatlibdnet-0:1.12-11.el6cf*
CloudForms Management Engine 5.4RedHatlshw-0:B.02.16-4.el6cf*
CloudForms Management Engine 5.4RedHatnetapp-manageability-sdk-0:4.0P1-3.el6cf*
CloudForms Management Engine 5.4RedHatopen-vm-tools-0:9.2.3-5.el6cf*
CloudForms Management Engine 5.4RedHatprince-0:9.0r2-4.el6cf*
CloudForms Management Engine 5.4RedHatpyliblzma-0:0.5.3-7.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-bcrypt-ruby-0:3.0.1-2.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-eventmachine-0:1.0.7-2.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-ffi-0:1.9.8-1.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-io-extra-0:1.2.8-1.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-json-0:1.8.2-2.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-nokogiri-0:1.5.11-2.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-pg-0:0.12.2-9.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-psych-0:2.0.13-1.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-qpid_messaging-0:0.20.2-5.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-therubyracer-0:0.11.0-5.el6cf*
CloudForms Management Engine 5.4RedHatruby200-rubygem-thin-0:1.3.1-9.el6cf*
CloudForms Management Engine 5.4RedHatsneakernet_ca-0:0.1-2.el6cf*
CloudForms Management Engine 5.4RedHatwmi-0:1.3.14-1.el6cf*
RailsUbuntuupstream*
Ruby-actionmailer-3.2Ubuntuquantal*
Ruby-actionmailer-3.2Ubunturaring*
Ruby-actionmailer-3.2Ubuntusaucy*
Ruby-actionmailer-3.2Ubuntuupstream*
Ruby-actionpack-2.3Ubuntuupstream*
Ruby-activerecord-2.3Ubuntuupstream*
Ruby-activesupport-2.3Ubuntuupstream*
Ruby-rails-2.3Ubuntuupstream*

Potential Mitigations

References