Input validation error - CVE-2013-1854

 

Input validation error - CVE-2013-1854

Published: March 20, 2013 / Updated: August 3, 2020


Vulnerability identifier: #VU33108
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2013-1854
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to perform service disruption.

The Active Record component in Ruby on Rails 2.3.x before 2.3.18, 3.1.x before 3.1.12, and 3.2.x before 3.2.13 processes certain queries by converting hash keys to symbols, which allows remote attackers to cause a denial of service via crafted input to a where method.


Affected software

libpng (Alpine package)
ruby-activerecord (Alpine package)

How to mitigate CVE-2013-1854

Install update from vendor's website.

libpng (Alpine package) - update to 1.4.12-r0
ruby-activerecord (Alpine package) - update to 2.3.18-r0

External References

Related Security Bulletins