openSUSE 安全更新:ruby (openSUSE-SU-2013:0278-1)

high Nessus 插件 ID 74881

简介

远程 openSUSE 主机缺少安全更新。

描述

此更新将 RubyOnRails 2.3 堆栈更新为 2.3.16,而且将 RubyOnRails 3.2 堆栈更新为 3.2.11。

完成了安全和缺陷补丁,最重要的是:CVE-2013-0333:修复了 JSON sql/code 注入问题。CVE-2012-5664:修复了 Active Record 中的 SQL 注入漏洞。CVE-2012-2695:修复了条件中通过嵌套的哈希的 SQL 注入。CVE-2013-0155:
修复了 Ruby on Rails 中的不安全查询生成风险。
CVE-2013-0156:修复了 Action Pack 内的参数解析中的多种漏洞。

解决方案

更新受影响的 ruby 程序包。

另见

https://bugzilla.novell.com/show_bug.cgi?id=766792

https://bugzilla.novell.com/show_bug.cgi?id=775649

https://bugzilla.novell.com/show_bug.cgi?id=775653

https://bugzilla.novell.com/show_bug.cgi?id=796712

https://bugzilla.novell.com/show_bug.cgi?id=797449

https://bugzilla.novell.com/show_bug.cgi?id=797452

https://bugzilla.novell.com/show_bug.cgi?id=798452

https://bugzilla.novell.com/show_bug.cgi?id=798458

https://bugzilla.novell.com/show_bug.cgi?id=800320

https://lists.opensuse.org/opensuse-updates/2013-02/msg00030.html

插件详情

严重性: High

ID: 74881

文件名: openSUSE-2013-106.nasl

版本: 1.8

类型: local

代理: unix

发布时间: 2014/6/13

最近更新时间: 2021/1/19

支持的传感器: Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent, Nessus

风险信息

VPR

风险因素: High

分数: 7.4

CVSS v2

风险因素: High

基本分数: 7.5

时间分数: 6.2

矢量: CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P

漏洞信息

CPE: p-cpe:/a:novell:opensuse:rubygem-actionmailer, p-cpe:/a:novell:opensuse:rubygem-actionmailer-2_3, p-cpe:/a:novell:opensuse:rubygem-actionmailer-2_3-testsuite, p-cpe:/a:novell:opensuse:rubygem-actionmailer-3_2, p-cpe:/a:novell:opensuse:rubygem-actionpack, p-cpe:/a:novell:opensuse:rubygem-actionpack-2_3, p-cpe:/a:novell:opensuse:rubygem-actionpack-2_3-testsuite, p-cpe:/a:novell:opensuse:rubygem-actionpack-3_2, p-cpe:/a:novell:opensuse:rubygem-activemodel-3_2, p-cpe:/a:novell:opensuse:rubygem-activerecord, p-cpe:/a:novell:opensuse:rubygem-activerecord-2_3, p-cpe:/a:novell:opensuse:rubygem-activerecord-2_3-testsuite, p-cpe:/a:novell:opensuse:rubygem-activerecord-3_2, p-cpe:/a:novell:opensuse:rubygem-activeresource, p-cpe:/a:novell:opensuse:rubygem-activeresource-2_3, p-cpe:/a:novell:opensuse:rubygem-activeresource-2_3-testsuite, p-cpe:/a:novell:opensuse:rubygem-activeresource-3_2, p-cpe:/a:novell:opensuse:rubygem-activesupport, p-cpe:/a:novell:opensuse:rubygem-activesupport-2_3, p-cpe:/a:novell:opensuse:rubygem-activesupport-3_2, p-cpe:/a:novell:opensuse:rubygem-rack-1_1, p-cpe:/a:novell:opensuse:rubygem-rack-1_1-testsuite, p-cpe:/a:novell:opensuse:rubygem-rack-1_2, p-cpe:/a:novell:opensuse:rubygem-rack-1_2-testsuite, p-cpe:/a:novell:opensuse:rubygem-rack-1_3, p-cpe:/a:novell:opensuse:rubygem-rack-1_3-testsuite, p-cpe:/a:novell:opensuse:rubygem-rack-1_4, p-cpe:/a:novell:opensuse:rubygem-rack-1_4-testsuite, p-cpe:/a:novell:opensuse:rubygem-rails, p-cpe:/a:novell:opensuse:rubygem-rails-2_3, p-cpe:/a:novell:opensuse:rubygem-rails-3_2, p-cpe:/a:novell:opensuse:rubygem-railties-3_2, p-cpe:/a:novell:opensuse:rubygem-sprockets-2_2, cpe:/o:novell:opensuse:12.1, cpe:/o:novell:opensuse:12.2

必需的 KB 项: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list, Host/cpu

可利用: true

易利用性: Exploits are available

补丁发布日期: 2013/2/4

可利用的方式

Metasploit (Ruby on Rails JSON Processor YAML Deserialization Code Execution)

参考资料信息

CVE: CVE-2012-2695, CVE-2012-6496, CVE-2013-0155, CVE-2013-0156, CVE-2013-0333