Description
actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2929-1 | ruby-actionpack-3.2 security update |
EUVD |
EUVD-2017-0186 | actionpack/lib/action_view/template/text.rb in Action View in Ruby on Rails 3.x before 3.2.17 converts MIME type strings to symbols during use of the :text option to the render method, which allows remote attackers to cause a denial of service (memory consumption) by including these strings in headers. |
Github GHSA |
GHSA-7cgp-c3g7-qvrw | actionpack Improper Input Validation vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T09:05:37.065Z
Reserved: 2013-12-03T00:00:00.000Z
Link: CVE-2014-0082
No data.
Status : Modified
Published: 2014-02-20T15:27:09.170
Modified: 2026-04-29T01:13:23.040
Link: CVE-2014-0082
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD
Github GHSA