CVE-2013-1855

NameCVE-2013-1855
DescriptionThe sanitize_css method in lib/action_controller/vendor/html-scanner/html/sanitizer.rb in the Action Pack component in Ruby on Rails before 2.3.18, 3.0.x and 3.1.x before 3.1.12, and 3.2.x before 3.2.13 does not properly handle \n (newline) characters, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via crafted Cascading Style Sheets (CSS) token sequences.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2655-1
NVD severitymedium (attack range: remote)
Debian Bugs703349

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rails (PTS)wheezy2:2.3.14.2fixed
jessie (security), jessie2:4.1.8-1+deb8u4fixed
stretch, sid2:4.2.7.1-1fixed
ruby-actionpack-2.3 (PTS)wheezy2.3.14-5fixed
ruby-actionpack-3.2 (PTS)wheezy3.2.6-6+deb7u2fixed
wheezy (security)3.2.6-6+deb7u3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
railssource(unstable)2.3.14.1medium
railssourcesqueeze2.3.5-1.2+squeeze8mediumDSA-2655-1
ruby-actionpack-2.3source(unstable)2.3.14-5medium
ruby-actionpack-3.2source(unstable)3.2.6-6medium703349

Notes

Starting with 2.3.14.1 rails is a transition package

Search for package or bug name: Reporting problems