Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
TRENDING TODAY
Home > News > Security > Security Blog

February 13th, 2013, 10:51 GMT · By

BLOG

Ruby on Rails 3.2.12, 3.1.11 and 2.3.17 Released to Address Security Holes

SHARE:

Adjust text size:


Ruby on Rails updated Enlarge picture - Ruby on Rails updated
The developers of Ruby on Rails have released versions 3.2.12, 3.1.11 and 2.3.17. Ruby on Rails 3.2.12 and 3.1.11 fix one security issue, while 2.3.17 addresses two additional vulnerabilities.

The first vulnerability (CVE-2013-0276) affects the attr_protected method in ActiveRecord and it could be exploited by an attacker to circumvent the protection and alter records by using a specially crafted request.

The second issue refers to a serialized attributes YAML issue that could be leveraged by cybercriminals for a denial-of-service (DOS) attack and even to remotely execute arbitrary code.

Finally, the latest updates address a DOS and unsafe object creation vulnerability in JSON.

Users are advised to update their installations as soon as possible to avoid any unfortunate incidents.

Ruby on Rails is available for download here

TELL US WHAT YOU THINK:

1,380 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Oracle to Release Updated Version of February 2013 CPU

Yahoo! SiteBuilder Comes with Highly Vulnerable Version of Java

Adobe Updates Flash Player 11.5 and 11.2 to Address 2 Zero-Day Vulnerabilities

PostgreSQL 9.2.3, 9.1.8, 9.0.12, 8.4.16, and 8.3.23 Released to Address DOS Bug

Oracle Fixes 50 Java Flaws with February CPU, One Vulnerability Still Unaddressed

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2013 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM