CVE-2013-6416
Publication date 7 December 2013
Last updated 24 July 2024
Ubuntu priority
Cross-site scripting (XSS) vulnerability in the simple_format helper in actionpack/lib/action_view/helpers/text_helper.rb in Ruby on Rails 4.x before 4.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML attribute.
Status
Package | Ubuntu Release | Status |
---|---|---|
rails | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Not affected
|
|
10.04 LTS lucid |
Not affected
|
|
ruby-actionpack-2.3 | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Not affected
|
|
10.04 LTS lucid | Not in release | |
ruby-actionpack-3.2 | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release | |
ruby-activerecord-2.3 | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Not affected
|
|
10.04 LTS lucid | Not in release | |
ruby-activerecord-3.2 | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release | |
ruby-activesupport-2.3 | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Not affected
|
|
10.04 LTS lucid | Not in release | |
ruby-activesupport-3.2 | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release | |
ruby-rails-2.3 | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise |
Not affected
|
|
10.04 LTS lucid | Not in release | |
ruby-rails-3.2 | 13.10 saucy |
Not affected
|
13.04 raring |
Not affected
|
|
12.10 quantal |
Not affected
|
|
12.04 LTS precise | Not in release | |
10.04 LTS lucid | Not in release |
Notes
mdeslaur
in Oneiric+, rails package is just for transition
seth-arnold
Only affected 4.0.x and higher