CVE-2013-0262
Published: 8 February 2013
rack/file.rb (Rack::File) in Rack 1.5.x before 1.5.2 and 1.4.x before 1.4.5 allows attackers to access arbitrary files outside the intended root directory via a crafted PATH_INFO environment variable, probably a directory traversal vulnerability that is remotely exploitable, aka "symlink path traversals."
Notes
Author | Note |
---|---|
jdstrand | per upstream, only 1.4 and higher |
Priority
Status
Package | Release | Status |
---|---|---|
ruby-rack Launchpad, Ubuntu, Debian |
hardy |
Does not exist
|
lucid |
Does not exist
|
|
oneiric |
Does not exist
|
|
precise |
Not vulnerable
(1.3.5-1)
|
|
quantal |
Ignored
(reached end-of-life)
|
|
raring |
Ignored
(reached end-of-life)
|
|
saucy |
Released
(1.5.2-1)
|
|
trusty |
Released
(1.5.2-1)
|
|
upstream |
Released
(1.4.5, 1.5.2)
|
|
Patches: upstream: https://github.com/rack/rack/commit/6f237e4c9fab649d3750482514f0fde76c56ab30 |