CVE-2013-0256
Published: 6 February 2013
darkfish.js in RDoc 2.3.0 through 3.12 and 4.x before 4.0.0.preview2.1, as used in Ruby, does not properly generate documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted URL.
Notes
Author | Note |
---|---|
jdstrand | rdoc part of ruby-defaults in Ubuntu 10.04 LTS and lower darkfish.js only present in ruby1.9.1 on Ubuntu 11.10 and later |
Priority
Status
Package | Release | Status |
---|---|---|
ruby-defaults Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Not vulnerable
(code-not-present)
|
|
oneiric |
Not vulnerable
|
|
precise |
Not vulnerable
|
|
quantal |
Not vulnerable
|
|
raring |
Not vulnerable
|
|
upstream |
Needs triage
|
|
ruby1.8 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Ignored
(end of life)
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Ignored
(end of life)
|
|
quantal |
Ignored
(end of life)
|
|
raring |
Ignored
(end of life)
|
|
upstream |
Needs triage
|
|
ruby1.9 Launchpad, Ubuntu, Debian |
hardy |
Ignored
(end of life)
|
lucid |
Ignored
(end of life)
|
|
maverick |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Does not exist
|
|
quantal |
Does not exist
|
|
raring |
Does not exist
|
|
upstream |
Needs triage
|
|
ruby1.9.1 Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Ignored
(end of life)
|
|
oneiric |
Ignored
(end of life)
|
|
precise |
Released
(1.9.3.0-1ubuntu2.5)
|
|
quantal |
Released
(1.9.3.194-1ubuntu1.3)
|
|
raring |
Released
(1.9.3.194-7ubuntu1)
|
|
upstream |
Released
(1.9.3.194-6)
|
|
Patches: upstream: https://github.com/rdoc/rdoc/commit/ffa87887ee0517793df7541629a470e331f9fe60 vendor: http://patch-tracker.debian.org/patch/series/view/ruby1.9.1/1.9.3.194-7/CVE-2013-0256.patch |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0256
- http://www.ruby-lang.org/en/news/2013/02/06/rdoc-xss-cve-2013-0256/
- http://blog.segment7.net/2013/02/06/rdoc-xss-vulnerability-cve-2013-0256-releases-3-9-5-3-12-1-4-0-0-rc-2
- https://ubuntu.com/security/notices/USN-1733-1
- NVD
- Launchpad
- Debian