CVE-2014-3482

NameCVE-2014-3482
DescriptionSQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, bugtraq, EDB, Metasploit, Red Hat, Ubuntu, Gentoo, SuSE, Mageia, GitHub code/issues, web search, more)
ReferencesDSA-2982-1
NVD severityhigh (attack range: remote)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
rails (PTS)wheezy2:2.3.14.2fixed
jessie (security), jessie2:4.1.8-1+deb8u4fixed
stretch2:4.2.7.1-1fixed
buster, sid2:4.2.9-4fixed
ruby-activerecord-2.3 (PTS)wheezy2.3.14-6vulnerable
ruby-activerecord-3.2 (PTS)wheezy3.2.6-5+deb7u1fixed
wheezy (security)3.2.6-5+deb7u3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
railssource(unstable)2:4.1.4-1high
railssourcesqueeze(unfixed)end-of-life
railssourcewheezy(not affected)
rails-3.2source(unstable)3.2.19-1high
rails-4.0source(unstable)(unfixed)high
ruby-activerecord-2.3source(unstable)(unfixed)high
ruby-activerecord-2.3sourcewheezy(unfixed)end-of-life
ruby-activerecord-3.2source(unstable)(unfixed)high
ruby-activerecord-3.2sourcewheezy3.2.6-5+deb7u1highDSA-2982-1

Notes

[wheezy] - rails <not-affected> (src:rails in wheezy is just a transition package)
[squeeze] - rails <end-of-life> (Unsupported in squeeze-lts)

Search for package or bug name: Reporting problems