oss-sec mailing list archives
CVE Request: ruby on rails header injection
From: Ludwig Nussel <ludwig.nussel () suse de>
Date: Wed, 19 Nov 2008 11:18:37 +0100
Hi, A header injection bug in ruby on rails was fixed some time ago but doesn't seem to have CVE number yet: http://www.rorsecurity.info/journal/2008/10/20/header-injection-and-response-splitting.html http://weblog.rubyonrails.org/2008/10/19/rails-2-0-5-redirect_to-and-offset-limit-sanitizing cu Ludwig -- (o_ Ludwig Nussel //\ V_/_ http://www.suse.de/ SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg)
Current thread:
- CVE Request: ruby on rails header injection Ludwig Nussel (Nov 19)
- Re: CVE Request: ruby on rails header injection Steven M. Christey (Nov 20)