Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
CVSS Details
- CVSS 3.1 Base Score: 5.3
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade ruby-actionmailer.Upgrade ruby-redmine-actionmailer. | Aug 30, 2017 | Oct 16, 2013 |
| Debian | — | Upgrade ruby-actionpack-3.2Upgrade ruby-actionmailer-3.2 | Jul 30, 2024 | Oct 17, 2013 |
| Ruby_on_rails | — | Upgrade to the latest version of Ruby on Rails | Jan 3, 2020 | Oct 17, 2013 |
| Suse | — | Upgrade rubygem-actionmailer-3_2-docUpgrade hawkUpgrade rubygem-actionpack-3_2-docUpgrade sle-hae-releaseUpgrade sle-sdk-releaseUpgrade rubygem-activesupport-3_2Upgrade hawk-templatesUpgrade rubygem-actionpack-3_2Upgrade rubygem-actionmailer-3_2Upgrade rubygem-activesupport-3_2-doc | Jan 9, 2014 | Oct 16, 2013 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub