CVE-2013-0263 (GCVE-0-2013-0263)
Vulnerability from cvelistv5
Published
2013-02-08 20:00
Modified
2024-08-06 14:18
Severity ?
CWE
  • n/a
Summary
Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.
References
secalert@redhat.com http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
secalert@redhat.com http://rack.github.com/ Vendor Advisory
secalert@redhat.com http://rhn.redhat.com/errata/RHSA-2013-0686.html
secalert@redhat.com http://secunia.com/advisories/52033 Vendor Advisory
secalert@redhat.com http://secunia.com/advisories/52134 Vendor Advisory
secalert@redhat.com http://secunia.com/advisories/52774
secalert@redhat.com http://www.debian.org/security/2013/dsa-2783
secalert@redhat.com http://www.osvdb.org/89939
secalert@redhat.com https://bugzilla.redhat.com/show_bug.cgi?id=909071
secalert@redhat.com https://gist.github.com/codahale/f9f3781f7b54985bee94
secalert@redhat.com https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07
secalert@redhat.com https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11
secalert@redhat.com https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J
secalert@redhat.com https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ
secalert@redhat.com https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ
secalert@redhat.com https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ
secalert@redhat.com https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ
secalert@redhat.com https://puppet.com/security/cve/cve-2013-0263
secalert@redhat.com https://twitter.com/coda/statuses/299732877745197056
af854a3a-2127-422b-91ae-364da2661108 http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
af854a3a-2127-422b-91ae-364da2661108 http://rack.github.com/ Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108 http://rhn.redhat.com/errata/RHSA-2013-0686.html
af854a3a-2127-422b-91ae-364da2661108 http://secunia.com/advisories/52033 Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108 http://secunia.com/advisories/52134 Vendor Advisory
af854a3a-2127-422b-91ae-364da2661108 http://secunia.com/advisories/52774
af854a3a-2127-422b-91ae-364da2661108 http://www.debian.org/security/2013/dsa-2783
af854a3a-2127-422b-91ae-364da2661108 http://www.osvdb.org/89939
af854a3a-2127-422b-91ae-364da2661108 https://bugzilla.redhat.com/show_bug.cgi?id=909071
af854a3a-2127-422b-91ae-364da2661108 https://gist.github.com/codahale/f9f3781f7b54985bee94
af854a3a-2127-422b-91ae-364da2661108 https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07
af854a3a-2127-422b-91ae-364da2661108 https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11
af854a3a-2127-422b-91ae-364da2661108 https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J
af854a3a-2127-422b-91ae-364da2661108 https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ
af854a3a-2127-422b-91ae-364da2661108 https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ
af854a3a-2127-422b-91ae-364da2661108 https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ
af854a3a-2127-422b-91ae-364da2661108 https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ
af854a3a-2127-422b-91ae-364da2661108 https://puppet.com/security/cve/cve-2013-0263
af854a3a-2127-422b-91ae-364da2661108 https://twitter.com/coda/statuses/299732877745197056
Impacted products
Vendor Product Version
n/a n/a Version: n/a
Show details on NVD website


{
  "containers": {
    "adp": [
      {
        "providerMetadata": {
          "dateUpdated": "2024-08-06T14:18:09.586Z",
          "orgId": "af854a3a-2127-422b-91ae-364da2661108",
          "shortName": "CVE"
        },
        "references": [
          {
            "name": "52774",
            "tags": [
              "third-party-advisory",
              "x_refsource_SECUNIA",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/52774"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11"
          },
          {
            "name": "52033",
            "tags": [
              "third-party-advisory",
              "x_refsource_SECUNIA",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/52033"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "http://rack.github.com/"
          },
          {
            "name": "52134",
            "tags": [
              "third-party-advisory",
              "x_refsource_SECUNIA",
              "x_transferred"
            ],
            "url": "http://secunia.com/advisories/52134"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://bugzilla.redhat.com/show_bug.cgi?id=909071"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ"
          },
          {
            "name": "RHSA-2013:0686",
            "tags": [
              "vendor-advisory",
              "x_refsource_REDHAT",
              "x_transferred"
            ],
            "url": "http://rhn.redhat.com/errata/RHSA-2013-0686.html"
          },
          {
            "name": "openSUSE-SU-2013:0462",
            "tags": [
              "vendor-advisory",
              "x_refsource_SUSE",
              "x_transferred"
            ],
            "url": "http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html"
          },
          {
            "tags": [
              "x_refsource_CONFIRM",
              "x_transferred"
            ],
            "url": "https://puppet.com/security/cve/cve-2013-0263"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://gist.github.com/codahale/f9f3781f7b54985bee94"
          },
          {
            "tags": [
              "x_refsource_MISC",
              "x_transferred"
            ],
            "url": "https://twitter.com/coda/statuses/299732877745197056"
          },
          {
            "name": "89939",
            "tags": [
              "vdb-entry",
              "x_refsource_OSVDB",
              "x_transferred"
            ],
            "url": "http://www.osvdb.org/89939"
          },
          {
            "name": "DSA-2783",
            "tags": [
              "vendor-advisory",
              "x_refsource_DEBIAN",
              "x_transferred"
            ],
            "url": "http://www.debian.org/security/2013/dsa-2783"
          }
        ],
        "title": "CVE Program Container"
      }
    ],
    "cna": {
      "affected": [
        {
          "product": "n/a",
          "vendor": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ],
      "datePublic": "2013-02-07T00:00:00",
      "descriptions": [
        {
          "lang": "en",
          "value": "Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time."
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "description": "n/a",
              "lang": "en",
              "type": "text"
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2017-12-08T10:57:01",
        "orgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
        "shortName": "redhat"
      },
      "references": [
        {
          "name": "52774",
          "tags": [
            "third-party-advisory",
            "x_refsource_SECUNIA"
          ],
          "url": "http://secunia.com/advisories/52774"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11"
        },
        {
          "name": "52033",
          "tags": [
            "third-party-advisory",
            "x_refsource_SECUNIA"
          ],
          "url": "http://secunia.com/advisories/52033"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "http://rack.github.com/"
        },
        {
          "name": "52134",
          "tags": [
            "third-party-advisory",
            "x_refsource_SECUNIA"
          ],
          "url": "http://secunia.com/advisories/52134"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://bugzilla.redhat.com/show_bug.cgi?id=909071"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ"
        },
        {
          "name": "RHSA-2013:0686",
          "tags": [
            "vendor-advisory",
            "x_refsource_REDHAT"
          ],
          "url": "http://rhn.redhat.com/errata/RHSA-2013-0686.html"
        },
        {
          "name": "openSUSE-SU-2013:0462",
          "tags": [
            "vendor-advisory",
            "x_refsource_SUSE"
          ],
          "url": "http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html"
        },
        {
          "tags": [
            "x_refsource_CONFIRM"
          ],
          "url": "https://puppet.com/security/cve/cve-2013-0263"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://gist.github.com/codahale/f9f3781f7b54985bee94"
        },
        {
          "tags": [
            "x_refsource_MISC"
          ],
          "url": "https://twitter.com/coda/statuses/299732877745197056"
        },
        {
          "name": "89939",
          "tags": [
            "vdb-entry",
            "x_refsource_OSVDB"
          ],
          "url": "http://www.osvdb.org/89939"
        },
        {
          "name": "DSA-2783",
          "tags": [
            "vendor-advisory",
            "x_refsource_DEBIAN"
          ],
          "url": "http://www.debian.org/security/2013/dsa-2783"
        }
      ]
    }
  },
  "cveMetadata": {
    "assignerOrgId": "53f830b8-0a3f-465b-8143-3b8a9948e749",
    "assignerShortName": "redhat",
    "cveId": "CVE-2013-0263",
    "datePublished": "2013-02-08T20:00:00",
    "dateReserved": "2012-12-06T00:00:00",
    "dateUpdated": "2024-08-06T14:18:09.586Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.1",
  "vulnerability-lookup:meta": {
    "nvd": "{\"cve\":{\"id\":\"CVE-2013-0263\",\"sourceIdentifier\":\"secalert@redhat.com\",\"published\":\"2013-02-08T20:55:01.640\",\"lastModified\":\"2025-04-11T00:51:21.963\",\"vulnStatus\":\"Deferred\",\"cveTags\":[],\"descriptions\":[{\"lang\":\"en\",\"value\":\"Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.\"},{\"lang\":\"es\",\"value\":\"Rack::Sesi\u00f3n::Cookie en rack v1.5.x antes de v1.5.2, v1.4.x antes de v1.4.5, v1.3.x antes de v1.3.10, v1.2.x antes de v1.2.8, antes de v1.1.x y v1.1.6 permite atacantes remotos para adivinar la cookie de sesi\u00f3n, los privilegios de ganancia, y ejecutar c\u00f3digo arbitrario a trav\u00e9s de un ataque de sincronizaci\u00f3n que implica una funci\u00f3n de comparaci\u00f3n HMAC que no se ejecuta en tiempo constante.\"}],\"metrics\":{\"cvssMetricV2\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"cvssData\":{\"version\":\"2.0\",\"vectorString\":\"AV:N/AC:H/Au:N/C:P/I:P/A:P\",\"baseScore\":5.1,\"accessVector\":\"NETWORK\",\"accessComplexity\":\"HIGH\",\"authentication\":\"NONE\",\"confidentialityImpact\":\"PARTIAL\",\"integrityImpact\":\"PARTIAL\",\"availabilityImpact\":\"PARTIAL\"},\"baseSeverity\":\"MEDIUM\",\"exploitabilityScore\":4.9,\"impactScore\":6.4,\"acInsufInfo\":false,\"obtainAllPrivilege\":false,\"obtainUserPrivilege\":false,\"obtainOtherPrivilege\":false,\"userInteractionRequired\":false}]},\"weaknesses\":[{\"source\":\"nvd@nist.gov\",\"type\":\"Primary\",\"description\":[{\"lang\":\"en\",\"value\":\"NVD-CWE-noinfo\"}]}],\"configurations\":[{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.5.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F55AF59F-CA0C-4F48-81BF-C9316672886D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.5.1:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"8DA5F2A1-86CC-4836-A75F-9B275884683A\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.4.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"2A3DD73E-6BD4-4C18-A4B8-AFA6860A4585\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.4.1:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"95E3FF6F-58C3-4491-BBD1-C4C13287A07D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.4.2:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"C04A5634-62C7-4B01-B644-06A6A1D5A828\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.4.3:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"290B1557-33F7-4717-B3C4-081FECF71BD5\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.4.4:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"FAB99ED2-4E74-4652-9A04-A46436F151E6\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"98CBCA07-8EEC-49D0-8C17-7887ABB63ED6\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.1:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"93B65658-8E1B-4832-822A-1C3770B33BB9\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.2:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"9E9E3412-6D9C-46FC-806E-0E0D310D4DDE\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.3:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"10A95FAF-3314-4F3F-8619-DAED41648AE3\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.4:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"00901558-9028-4BDF-AFE6-502DF2632069\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.5:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"5A8CBC63-DBA8-4A4E-87D7-5B891CDF7091\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.6:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"8F6A8485-8F4B-42E8-81ED-84CE5CE8E27D\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.7:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"FBEE2AAF-1575-44F7-9B1B-87504E0425E0\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.8:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"384FC6D2-443E-4810-B40A-EB90E74CC692\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.3.9:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"DB5D71EF-9B75-4031-8893-2630FC041444\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.2.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F4ECE38D-E0CA-4C37-B6A7-385F90FA3BC6\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.2.1:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"8B347613-F3F6-490C-AAE7-A5054B7D2892\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.2.2:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"FDA365EF-8CF1-4040-9353-00F0BF0499C0\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.2.3:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"A27A3B18-AB5A-4F99-AD51-12870745D9FA\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.2.4:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"C207F012-CEEE-4173-A64D-61A8E8E02533\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.2.6:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"C9E6D296-9514-40E4-A931-1C303C214D0A\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.2.7:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"C17E27F8-2348-4642-9E7E-5FA60C9C0E6C\"}]}]},{\"nodes\":[{\"operator\":\"OR\",\"negate\":false,\"cpeMatch\":[{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.1.0:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"9A68A97A-A85D-4825-8D23-FDFB45894C89\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.1.4:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"46D0BD4F-B060-425E-8EC9-B79795635C41\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.1.5:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"F4FA282B-BE5C-4B92-A1DC-A00F5A6EEFF0\"},{\"vulnerable\":true,\"criteria\":\"cpe:2.3:a:rack_project:rack:1.1.6:*:*:*:*:*:*:*\",\"matchCriteriaId\":\"01C614AE-D333-49C4-B65D-9FD7B7445AC6\"}]}]}],\"references\":[{\"url\":\"http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://rack.github.com/\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"http://rhn.redhat.com/errata/RHSA-2013-0686.html\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://secunia.com/advisories/52033\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"http://secunia.com/advisories/52134\",\"source\":\"secalert@redhat.com\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"http://secunia.com/advisories/52774\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://www.debian.org/security/2013/dsa-2783\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://www.osvdb.org/89939\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=909071\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://gist.github.com/codahale/f9f3781f7b54985bee94\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://puppet.com/security/cve/cve-2013-0263\",\"source\":\"secalert@redhat.com\"},{\"url\":\"https://twitter.com/coda/statuses/299732877745197056\",\"source\":\"secalert@redhat.com\"},{\"url\":\"http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://rack.github.com/\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"http://rhn.redhat.com/errata/RHSA-2013-0686.html\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://secunia.com/advisories/52033\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"http://secunia.com/advisories/52134\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\",\"tags\":[\"Vendor Advisory\"]},{\"url\":\"http://secunia.com/advisories/52774\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://www.debian.org/security/2013/dsa-2783\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"http://www.osvdb.org/89939\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://bugzilla.redhat.com/show_bug.cgi?id=909071\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://gist.github.com/codahale/f9f3781f7b54985bee94\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://puppet.com/security/cve/cve-2013-0263\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"},{\"url\":\"https://twitter.com/coda/statuses/299732877745197056\",\"source\":\"af854a3a-2127-422b-91ae-364da2661108\"}]}}"
  }
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…