FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2013-6414

This CVE name corresponds to:

Entered Topic
2013-12-08 rails -- multiple vulnerabilities

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2013-6414
Phase Assigned(20131104)

Description

actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.

References

Source Reference
MLIST [ruby-security-ann] 20131203 [CVE-2013-6414] Denial of Service Vulnerability in Action View
CONFIRM http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/
CONFIRM http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/
DEBIAN DSA-2888
REDHAT RHSA-2013:1794
REDHAT RHSA-2014:0008
REDHAT RHSA-2014:1863
SUSE openSUSE-SU-2013:1904
SUSE openSUSE-SU-2013:1906
SUSE openSUSE-SU-2013:1907
SUSE openSUSE-SU-2014:0009
SECUNIA 57836