Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2011-3186

Overview

Vulnerability Score 4.3 4.3
CVE Id CVE-2011-3186
Last Modified 06 Jul 2012 12:00:00
Published 29 Aug 2011 02:55:01
Confidentiality Impact NONE NONE
Integrity Impact PARTIAL PARTIAL
Availability Impact NONE NONE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2011-3186

Summary

CRLF injection vulnerability in actionpack/lib/action_controller/response.rb in Ruby on Rails 2.3.x before 2.3.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the Content-Type header.

Vulnerable Systems

Application

  • Ruby On Rails 2.3.10

  • Ruby On Rails 2.3.11

  • Ruby On Rails 2.3.12

  • Ruby On Rails 2.3.2

  • Ruby On Rails 2.3.3

  • Ruby On Rails 2.3.4

  • Ruby On Rails 2.3.9

  • Rubyonrails Ruby On Rails 2.3.10

  • Rubyonrails Ruby On Rails 2.3.11

  • Rubyonrails Ruby On Rails 2.3.12

  • Rubyonrails Ruby On Rails 2.3.2

  • Rubyonrails Ruby On Rails 2.3.3

  • Rubyonrails Ruby On Rails 2.3.4

  • Rubyonrails Ruby On Rails 2.3.9


References

CONFIRM - https://github.com/rails/rails/commit/11dafeaa7533be26441a63618be93a03869c83a9

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=732156

MLIST - [oss-security] 20110822 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110820 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110819 Re: CVE request: ruby on rails flaws (4)

MLIST - [oss-security] 20110817 CVE request: ruby on rails flaws (4)

MLIST - [rubyonrails-security] 20110816 Response Splitting Vulnerability in Ruby on Rails

DEBIAN - DSA-2301

SECUNIA - 45921

FEDORA - FEDORA-2011-11567


Last Updated: 27 May 2016 10:53:33