CVE-2013-6414
published 2013-12-07CVE-2013-6414: actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial…
PriorityP336medium5CVSS 2.0
AVNACLAuNCNINAP
EXPLOIT
EPSS
20.70%
97.3th percentile
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
Affected
56 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| actionpack_project | actionpack | >= 3.0.0 < 3.2.16 | 3.2.16 |
| actionpack_project | actionpack | >= 4.0.0 < 4.0.2 | 4.0.2 |
| debian | rails | — | — |
| rubyonrails | rails | <= 4.0.1 | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
| rubyonrails | rails | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploit vector is a specially crafted HTTP Content-Type header containing an invalid MIME type sent to a Ruby on Rails application; detect anomalous or malformed MIME type values in incoming Content-Type headers ↗
- →The vulnerable code path is in actionpack/lib/action_view/lookup_context.rb; monitor for unbounded memory growth in Rails worker processes as an indicator of active exploitation ↗
- →Affected versions are Rails 3.0.0 through 3.2.15 and 4.0.0 through 4.0.1; presence of these versions in a deployed application indicates exploitability ↗
- →Upstream fix commits can be used to diff and build YARA/code-level signatures for the vulnerable vs. patched lookup_context.rb ↗
- ·The DoS requires a controller action to be reachable; applications with no publicly accessible Rails controller actions are not exploitable via this vector ↗
- ·Rails 2.3.x is not affected; only 3.0.0 and later (up to the fixed versions) are vulnerable ↗
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_debian5.0LOW
vendor_redhat5.0MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
actionpack Improper Input Validation vulnerability
ghsa·2017-10-24
CVE-2013-6414 [MEDIUM] CWE-20 actionpack Improper Input Validation vulnerability
actionpack Improper Input Validation vulnerability
`actionpack/lib/action_view/lookup_context.rb` in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
OSV
actionpack Improper Input Validation vulnerability
osv·2017-10-24
CVE-2013-6414 [MEDIUM] actionpack Improper Input Validation vulnerability
actionpack Improper Input Validation vulnerability
`actionpack/lib/action_view/lookup_context.rb` in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
OSV
CVE-2013-6414: actionpack/lib/action_view/lookup_context
osv·2013-12-07·CVSS 5.0
CVE-2013-6414 [MEDIUM] CVE-2013-6414: actionpack/lib/action_view/lookup_context
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
Red Hat
rubygem-actionpack: Action View DoS
vendor_redhat·2013-12-03·CVSS 5.0
CVE-2013-6414 [MEDIUM] CWE-400 rubygem-actionpack: Action View DoS
rubygem-actionpack: Action View DoS
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
A denial of service flaw was found in the header handling component of Action View. A remote attacker could send strings in specially crafted headers that would be cached indefinitely, which would result in all available system memory eventually being consumed.
Package: ruby193-rubygem-actionpack (CloudForms Management Engine 5) - Will not fix
Package: ruby193-rubygem-actionpack (OpenShift Enterprise 1) - Will not fix
Package: ruby193-rubygem-actionpack (Red Hat OpenStack Platform 4) -
Debian
CVE-2013-6414: rails - actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x...
vendor_debian·2013·CVSS 5.0
CVE-2013-6414 [MEDIUM] CVE-2013-6414: rails - actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x...
actionpack/lib/action_view/lookup_context.rb in Action View in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allows remote attackers to cause a denial of service (memory consumption) via a header containing an invalid MIME type that leads to excessive caching.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
No detection rules found.
Bugzilla
CVE-2014-6414 openstack-neutron: Admin-only network attributes may be reset to defaults by non-privileged users
bugzilla·2014-09-16·CVSS 4.0
CVE-2014-6414 [MEDIUM] CVE-2014-6414 openstack-neutron: Admin-only network attributes may be reset to defaults by non-privileged users
CVE-2014-6414 openstack-neutron: Admin-only network attributes may be reset to defaults by non-privileged users
The OpenStack project reports:
""
Title: Admin-only network attributes may be reset to defaults by
non-privileged users
Reporter: Elena Ezhova (Mirantis)
Products: Neutron
Versions: up to 2013.2.4 and 2014.1 versions up to 2014.1.2
Description:
Elena Ezhova from Mirantis reported a vulnerability in Neutron. By updating
a network attribute with a default value a non-privileged user may reset
admin-only network attributes. This may lead to unexpected behavior with
security implications for operators with a custom policy.json, or in some
extreme cases network outages resulting in denial of service. All
deployments using neutron networking are affected by this flaw.
""
References
Bugzilla
CVE-2013-6414 rubygem-actionpack: Action View DoS
bugzilla·2013-12-02·CVSS 5.0
CVE-2013-6414 [MEDIUM] CVE-2013-6414 rubygem-actionpack: Action View DoS
CVE-2013-6414 rubygem-actionpack: Action View DoS
Michael Koziarski reports:
Strings sent in specially crafted headers will be cached indefinitely. This
can cause the cache to grow infinitely, which will eventually consume all
memory on the target machine, causing a denial of service.
Discussion:
Quoting further details form the upstream advisory draft:
Denial of Service Vulnerability in Action View
There is a denial of service vulnerability in the header handling component of Action View. This vulnerability has been assigned the CVE identifier CVE-2013-6414.
Versions Affected: 3.0.0 and all later versions
Not affected: 2.3.x
Fixed Versions: 4.0.2, 3.2.16
Impact
Strings sent in specially crafted headers will be cached indefinitely. This can cause the cache to grow infinitely, whic
http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1794.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0008.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://secunia.com/advisories/57836http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2014/dsa-2888http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/https://groups.google.com/forum/message/raw?msg=ruby-security-ann/A-ebV4WxzKg/KNPTbX8XAQUJhttps://puppet.com/security/cve/cve-2013-6414http://lists.opensuse.org/opensuse-updates/2013-12/msg00079.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00081.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00082.htmlhttp://lists.opensuse.org/opensuse-updates/2014-01/msg00003.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1794.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0008.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1863.htmlhttp://secunia.com/advisories/57836http://weblog.rubyonrails.org/2013/12/3/Rails_3_2_16_and_4_0_2_have_been_released/http://www.debian.org/security/2014/dsa-2888http://www.getchef.com/blog/2014/04/09/enterprise-chef-11-1-3-release/https://groups.google.com/forum/message/raw?msg=ruby-security-ann/A-ebV4WxzKg/KNPTbX8XAQUJhttps://puppet.com/security/cve/cve-2013-6414
2013-12-07
Published