CVE-2013-4389
published 2013-10-17CVE-2013-4389: Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow…
PriorityP420medium4.3CVSS 2.0
AVNACMAuNCNINAP
EPSS
3.14%
86.6th percentile
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | rails | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| rubyonrails | rails | >= 3.0.0 < 3.2.15 | 3.2.15 |
CVSS provenance
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
osv4.3MEDIUM
vendor_debian4.3LOW
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
actionmailer email address processing causes Denial of service
ghsa·2017-10-24
CVE-2013-4389 [MEDIUM] CWE-134 actionmailer email address processing causes Denial of service
actionmailer email address processing causes Denial of service
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
OSV
actionmailer email address processing causes Denial of service
osv·2017-10-24
CVE-2013-4389 [MEDIUM] actionmailer email address processing causes Denial of service
actionmailer email address processing causes Denial of service
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
OSV
CVE-2013-4389: Multiple format string vulnerabilities in log_subscriber
osv·2013-10-17·CVSS 4.3
CVE-2013-4389 [MEDIUM] CVE-2013-4389: Multiple format string vulnerabilities in log_subscriber
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
Red Hat
rubygem-actionmailer: email address processing DoS
vendor_redhat·2013-10-16·CVSS 4.3
CVE-2013-4389 [MEDIUM] CWE-134 rubygem-actionmailer: email address processing DoS
rubygem-actionmailer: email address processing DoS
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
Statement: Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
This issue did not affect the versions of rubygem-actionmailer as shipped with Red Hat Subscription Asset Manager 1 as they do not include support for sending e
Debian
CVE-2013-4389: rails - Multiple format string vulnerabilities in log_subscriber.rb files in the log sub...
vendor_debian·2013·CVSS 4.3
CVE-2013-4389 [MEDIUM] CVE-2013-4389: rails - Multiple format string vulnerabilities in log_subscriber.rb files in the log sub...
Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4389 rubygem-actionmailer: email address processing DoS [fedora-all]
bugzilla·2013-11-27·CVSS 4.3
CVE-2013-4389 [MEDIUM] CVE-2013-4389 rubygem-actionmailer: email address processing DoS [fedora-all]
CVE-2013-4389 rubygem-actionmailer: email address processing DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
Bugzilla
CVE-2013-4389 rubygem-actionmailer: email address processing DoS
bugzilla·2013-10-01·CVSS 4.3
CVE-2013-4389 [MEDIUM] CVE-2013-4389 rubygem-actionmailer: email address processing DoS
CVE-2013-4389 rubygem-actionmailer: email address processing DoS
Aaron Patterson reports:
Possible DoS Vulnerability in Action Mailer
There is a possible DoS vulnerability in the log subscriber component of
Action Mailer. This vulnerability has been assigned the CVE identifier CVE-2013-4389.
Versions Affected: 3.x.x
Not affected: 4.0.x, 2.3.x
Fixed Versions: 3.2.15
Impact
A carefully crafted email address in conjunction with the Action Mailer logger
format string could possibly lead to a denial of service attack.
All users running an affected release should either upgrade or use one of the
work arounds immediately.
Releases
The FIXED releases are available at the normal locations.
Workarounds
If you can't upgrade or apply patch to your system, you can work around the
issue by using
http://lists.opensuse.org/opensuse-updates/2013-12/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00094.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://www.debian.org/security/2014/dsa-2887http://www.debian.org/security/2014/dsa-2888https://groups.google.com/forum/message/raw?msg=ruby-security-ann/yvlR1Vx44c8/elKJkpO2KVgJhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00091.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00094.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://www.debian.org/security/2014/dsa-2887http://www.debian.org/security/2014/dsa-2888https://groups.google.com/forum/message/raw?msg=ruby-security-ann/yvlR1Vx44c8/elKJkpO2KVgJ
2013-10-17
Published