UBUNTU-CVE-2012-6496
Dashboard / Vulnerabilities / UBUNTU-CVE-2012-6496
Summary:
Details: SQL injection vulnerability in the Active Record component in Ruby on Rails before 3.0.18, 3.1.x before 3.1.9, and 3.2.x before 3.2.10 allows remote attackers to execute arbitrary SQL commands via a crafted request that leverages incorrect behavior of dynamic finders in applications that can use unexpected data types in certain find_by_ method calls.
References: https://ubuntu.com/security/CVE-2012-6496, http://www.openwall.com/lists/oss-security/2013/01/03/5, http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts, https://groups.google.com/forum/#!topic/rubyonrails-security/DCNTNp_qjFM, http://www.openwall.com/lists/oss-security/2013/01/03/12, https://www.cve.org/CVERecord?id=CVE-2012-6496
Affected packages
Package
Name: ruby-activerecord-3.2
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
