Sha256: 27b4902a30796500d845fe3f7b5c115b06c95d4348b8af519417d2cebdfe1fd9

Contents?: true

Size: 723 Bytes

Versions: 5

Compression:

Stored size: 723 Bytes

Contents

---
gem: actionpack
framework: rails
cve: 2012-3424
osvdb: 84243
url: http://www.osvdb.org/show/osvdb/84243
title:
  Ruby on Rails actionpack/lib/action_controller/metal/http_authentication.rb
  with_http_digest Helper Method Remote DoS
date: 2012-07-26

description: |
  Ruby on Rails contains a flaw that may allow a remote denial of service.
  The issue is triggered when an error occurs in
  actionpack/lib/action_controller/metal/http_authentication.rb when the
  with_http_digest helper method is being used. This may allow a remote
  attacker to cause a loss of availability for the program.

cvss_v2: 5.0

unaffected_versions:
  - ">= 2.3.5, <= 2.3.14"

patched_versions:
  - ~> 3.0.16
  - ~> 3.1.7
  - ">= 3.2.7"

Version data entries

5 entries across 5 versions & 2 rubygems

Version Path
bundler-budit-0.6.2 data/ruby-advisory-db/gems/actionpack/OSVDB-84243.yml
bundler-budit-0.6.1 data/ruby-advisory-db/gems/actionpack/OSVDB-84243.yml
bundler-audit-0.6.1 data/ruby-advisory-db/gems/actionpack/OSVDB-84243.yml
bundler-audit-0.6.0 data/ruby-advisory-db/gems/actionpack/OSVDB-84243.yml
bundler-audit-0.5.0 data/ruby-advisory-db/gems/actionpack/OSVDB-84243.yml