Asymmetric denial of service In actionmailer
Description
actionmailer email address processing causes Denial of service Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.
Mitigation
Update Impact
Minimal update. May introduce new vulnerabilities or breaking changes.
Ecosystem | Component | Affected version | Patched versions |
|---|---|---|---|
rubygems | 3.2.15 |
Aliases
1. 2. 3. 4. 5.
References
1. 2. 3. 4. 5. 6. 7.