CVE-2011-3187 Information

Description

The to_s method in actionpack/lib/action_dispatch/middleware/remote_ip.rb in Ruby on Rails 3.0.5 does not validate the X-Forwarded-For header in requests from IP addresses on a Class C network which might allow remote attackers to inject arbitrary text into log files or bypass intended address parsing via a crafted header.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2011-02/0337.html http://webservsec.blogspot.com/2011/02/ruby-on-rails-vulnerability.html http://www.openwall.com/lists/oss-security/2011/08/17/1 http://www.openwall.com/lists/oss-security/2011/08/19/11 http://www.openwall.com/lists/oss-security/2011/08/20/1 http://www.openwall.com/lists/oss-security/2011/08/22/13 http://www.openwall.com/lists/oss-security/2011/08/22/14 http://www.openwall.com/lists/oss-security/2011/08/22/5 https://bugzilla.novell.com/show_bug.cgi?id=673010

Share on: