Common Vulnerabilities and Exposures assigned an identifier CVE-2011-0448 to the following vulnerability: Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument. References: [1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2011-0448 [2] http://groups.google.com/group/rubyonrails-security/msg/4e19864cf6ad40ad?dmode=source&output=gplain [3] http://weblog.rubyonrails.org/2011/2/8/new-releases-2-3-11-and-3-0-4 [4] http://securitytracker.com/id?1025063 [5] http://secunia.com/advisories/43278
rubygem-activerecord-3.0.5-1.fc15 has been submitted as an update for Fedora 15. https://admin.fedoraproject.org/updates/rubygem-activesupport-3.0.5-1.fc15,rubygem-activemodel-3.0.5-1.fc15,rubygem-activeresource-3.0.5-1.fc15,rubygem-activerecord-3.0.5-1.fc15,rubygem-actionpack-3.0.5-1.fc15,rubygem-actionmailer-3.0.5-1.fc15,rubygem-railties-3.0.5-1.fc15,rubygem-rails-3.0.5-2.fc15