CVE-2014-3482
ruby-activerecord-3.2 - security update
EPSS 1.5%
Description
SQL injection vulnerability in activerecord/lib/active_record/connection_adapters/postgresql_adapter.rb in the PostgreSQL adapter for Active Record in Ruby on Rails 2.x and 3.x before 3.2.19 allows remote attackers to execute arbitrary SQL commands by leveraging improper bitstring quoting.
How to fix CVE-2014-3482
To remediate CVE-2014-3482, upgrade the affected package to a fixed version below.
- Debian/rails—upgrade to 2:4.1.4-1 or later
- Debian/ruby-activerecord-3.2—upgrade to 3.2.6-5+deb7u1 or later
- —upgrade to 3.2.19 or later
Is CVE-2014-3482 being exploited?
Low — EPSS is 1.5%, meaning exploitation activity has not been observed at scale.
Affected packages (3)
- from 0, < 2:4.1.4-1
- from 0, < 3.2.6-5+deb7u1
- >= 2.0.0, < 3.2.19