Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

June 1st, 2012, 14:01 GMT · By

BLOG

Critical SQL Injection Vulnerability Fixed with Ruby on Rails 3.2.5

SHARE:

Adjust text size:


SQL Injection vulnerability fixed in Ruby on Rails Enlarge picture - SQL Injection vulnerability fixed in Ruby on Rails
A critical SQL Injection vulnerability has been found to affect the Ruby on Rails web framework and, as a result, the developers have released the 3.2.4 and, shortly after, the 3.2.5 variant to address this and other issues.

The SQL Injection security hole was present in Active Record and affected all versions starting with 3.0. Ruby on Rails 2.3.14 has not been impacted by the flaw.

Identified by Ben Murphy, the weakness occurred due to the way in which Active Record handled nested query parameters. The bug allowed an attacker to inject SLQ commands into an app’s SQL queries with the aid of a specially crafted request.

Customers of Ruby on Rails 3.0 and later versions are advised to immediately apply the updates.

Ruby on Rails 3.2.5 is available for download here

TELL US WHAT YOU THINK:

2,258 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hackers Ready iOS 6 Jailbreak Before Apple Even Rolls Out the Betas (Updated)

Critical 0-Day in Hotmail Exploited in the Wild, Microsoft Issues Fix (Updated)

Experts: Flame Not the Next Stuxnet, but It Could Be

Hackers Breach MyBB.com, Site Taken Offline (Updated)

Bitcoin Developers Address Denial-of-Service Vulnerability

READER COMMENTS:


Comment #1 by: Coder-Joe on 08 Jan 2013, 09:00 UTC reply to this comment

Thanks for the information. helpful to know, that our RoR version is already save ;-) It's good to keep the software always up to date...
is a link possible?

Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM