CVE-2011-0448
Publication date 21 February 2011
Last updated 24 July 2024
Ubuntu priority
Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.
Status
Package | Ubuntu Release | Status |
---|---|---|
rails | 10.10 maverick |
Not affected
|
10.04 LTS lucid |
Not affected
|
|
9.10 karmic |
Not affected
|
|
8.04 LTS hardy |
Not affected
|
|
6.06 LTS dapper |
Not affected
|