[v2.7] ruby-rails: vulnerabilities in PostgreSQL adapter for Active Record (CVE-2014-3482 CVE-2014-3483)
There are two distinct but related vulnerabilities in PostgreSQL adapter for Active Record. These vulnerabilities have been assigned the CVE identifiers CVE-2014-3482 and CVE-2014-3483.
Versions Affected: All Versions >2.0
Not affected: Databases other than PostgreSQL
Fixed Versions: 3.2.19, 4.0.7 & 4.1.3
References:
CONFIRM: http://seclists.org/oss-sec/2014/q3/5
CONFIRM:
http://weblog.rubyonrails.org/2014/7/2/Rails\_3\_2\_19\_4\_0\_7\_and\_4\_1\_3\_have\_been\_released/
(from redmine: issue id 3152, created on 2014-07-03, closed on 2015-05-22)
- Relations:
- parent #3149 (closed)
- Changesets:
- Revision e9cf2371 by Kaarle Ritvanen on 2014-12-09T00:24:13Z:
ruby-rails: upgrade to 4.0.12 (CVE-2013-0334, CVE-2014-3482, CVE-2014-3483, CVE-2014-3514, CVE-2014-7818, CVE-2014-7819)
fixes #3152
fixes #3332
fixes #3475
fixes #3581
fixes #3585
- Revision dad22154 by Kaarle Ritvanen on 2014-12-09T00:29:57Z:
ruby-redmine-rails: upgrade to 3.2.21 (CVE-2014-3482, CVE-2014-3483, CVE-2014-7818, CVE-2014-7819)
fixes #3152
fixes #3581
fixes #3585