CVE-2013-0269
Publication date 12 February 2013
Last updated 24 July 2024
Ubuntu priority
The JSON gem before 1.5.5, 1.6.x before 1.6.8, and 1.7.x before 1.7.7 for Ruby allows remote attackers to cause a denial of service (resource consumption) or bypass the mass assignment protection mechanism via a crafted JSON document that triggers the creation of arbitrary Ruby symbols or certain internal objects, as demonstrated by conducting a SQL injection attack against Ruby on Rails, aka "Unsafe Object Creation Vulnerability."
Status
Package | Ubuntu Release | Status |
---|---|---|
ruby-json | ||
16.04 LTS xenial |
Not affected
|
|
14.04 LTS trusty |
Not affected
|
|
ruby1.9.1 | ||
16.04 LTS xenial | Not in release | |
14.04 LTS trusty |
Fixed 1.9.3.194-7ubuntu1
|
|
Notes
seth-arnold
1.7 patch was updated, see second Google groups reference, the upstream patch URL given here is the updated patch.
Patch details
References
Related Ubuntu Security Notices (USN)
- USN-1733-1
- Ruby vulnerabilities
- 21 February 2013