Back to bug 1036483

Who When What Removed Added
Garth Mollett 2013-12-02 06:22:39 UTC CC security-response-team
Red Hat Bugzilla 2013-12-02 06:22:39 UTC Doc Type --- Bug Fix
Garth Mollett 2013-12-02 06:23:43 UTC CC abaron, aortega, apevec, ayoung, bdunne, bgollahe, bkearney, bleanhar, briang, ccoleman, chrisw, cpelland, dallan, dmcphers, drieden, gkotton, hateya, jdetiber, jfrey, jialiu, jomara, jrafanie, kseifried, lhh, lmeyer, markmc, mmaslano, mmccune, obarenbo, pmyers, rbryant, sclewis, tdawson, tkramer, vondruch, xlecauch, yeylon
Garth Mollett 2013-12-02 06:31:13 UTC Blocks 1036487
Tomas Hoger 2013-12-02 20:06:26 UTC Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=7.8/AV:N/AC:L/Au:N/C:N/I:N/A:C,fedora-all/rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack-3.2.13-3.el6cf=affected,rhscl-1.0.z/rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openshift-enterprise-1/ruby193-rubygem-actionpack=affected,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=affected,openshift-enterprise-1/ruby193-rubygem-actionpack=affected,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected
Tomas Hoger 2013-12-02 20:08:10 UTC Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=affected,openshift-enterprise-1/ruby193-rubygem-actionpack=affected,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=affected,openshift-enterprise-1/ruby193-rubygem-actionpack=affected,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected
Tomas Hoger 2013-12-02 20:15:33 UTC Fixed In Version rubygem-actionpack 3.2.16, rubygem-actionpack 4.0.2
Tomas Hoger 2013-12-02 22:02:24 UTC Blocks 1036487
Tomas Hoger 2013-12-02 22:07:53 UTC Blocks 1036411
Tomas Hoger 2013-12-03 09:13:24 UTC Depends On 1036420
Tomas Hoger 2013-12-03 09:31:45 UTC Depends On 1037487
Tomas Hoger 2013-12-03 09:33:18 UTC Depends On 1036421
Tomas Hoger 2013-12-04 08:41:55 UTC Summary EMBARGOED CVE-2013-6414 rubygem-actionpack: Action View DoS CVE-2013-6414 rubygem-actionpack: Action View DoS
Tomas Hoger 2013-12-04 08:42:09 UTC Group security, qe_staff
Kurt Seifried 2013-12-18 03:44:48 UTC Depends On 1036415
John Skeoch 2014-01-13 01:08:13 UTC CC hateya
John Skeoch 2014-03-17 02:02:32 UTC CC abaron iheim
John Skeoch 2014-06-18 07:58:36 UTC CC tkramer mmcgrath
Garth Mollett 2014-06-23 13:09:17 UTC Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=affected,openshift-enterprise-1/ruby193-rubygem-actionpack=affected,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=affected,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected
John Skeoch 2014-06-24 00:10:31 UTC CC dallan
Kurt Seifried 2014-07-16 04:53:40 UTC Depends On 1120007
Kurt Seifried 2014-07-16 04:53:48 UTC Depends On 1120008
Kurt Seifried 2014-10-28 23:09:43 UTC Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=affected,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected
Kurt Seifried 2014-11-01 01:23:47 UTC Depends On 1159438
Kurt Seifried 2014-11-04 20:34:21 UTC Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=affected,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=wontfix,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected
Kurt Seifried 2014-11-06 06:02:26 UTC Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=wontfix,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=wontfix,sam-1/rubygem-actionpack=wontfix,cfme-5/ruby193-rubygem-actionpack=wontfix,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected
Kurt Seifried 2014-11-06 06:05:25 UTC Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=wontfix,sam-1/rubygem-actionpack=wontfix,cfme-5/ruby193-rubygem-actionpack=wontfix,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=wontfix,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected
John Skeoch 2014-11-09 22:57:15 UTC CC jomara athomas
Kurt Seifried 2014-11-13 06:10:14 UTC Blocks 1000138
Martin Prpič 2014-11-14 16:21:16 UTC Doc Text A denial of service flaw was found in the header handling component of Action View. A remote attacker could send strings in specially crafted headers that would be cached indefinitely, which would result in all available system memory eventually being consumed.
Kurt Seifried 2014-11-18 20:47:29 UTC Depends On 1165364
Kurt Seifried 2014-11-18 20:47:35 UTC Depends On 1165365
Ján Rusnačko 2014-11-21 09:07:18 UTC CC jrusnack
Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=wontfix,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=wontfix,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected,cwe=CWE-400
Kurt Seifried 2015-01-17 05:35:33 UTC Status NEW CLOSED
Resolution --- ERRATA
Last Closed 2015-01-17 00:35:33 UTC
Perry Myers 2016-04-27 03:08:08 UTC CC pmyers
Product Security DevOps Team 2019-09-29 13:10:38 UTC Whiteboard impact=moderate,public=20131203,reported=20131201,source=distros,cvss2=5/AV:N/AC:L/Au:N/C:N/I:N/A:P,rhscl-1/ruby193-rubygem-actionpack=affected,rhscl-1.1/ruby200-rubygem-actionpack=affected,sam-1/ruby193-rubygem-actionpack=affected,sam-1/rubygem-actionpack=affected,cfme-5/ruby193-rubygem-actionpack=wontfix,openstack-3/ruby193-rubygem-actionpack=affected,openstack-4/ruby193-rubygem-actionpack=notaffected,openshift-enterprise-1/ruby193-rubygem-actionpack=wontfix,openshift-1/ruby193-rubygem-actionpack=affected,openshift-1/rubygem-actionpack=affected,rhn_satellite_6/ruby193-rubygem-actionpack=affected,fedora-all/rubygem-actionpack=affected,epel-5/rubygem-actionpack=notaffected,cwe=CWE-400
Tomas Hoger 2020-02-28 15:44:42 UTC CC hhorak, jorton, ruby-maint

Back to bug 1036483