CVE Database
/

CVE-2009-3086

Back to search

CVE-2009-3086

Published: Sep 8, 2009

Modified: Aug 7, 2024

PUBLISHED

Description

A certain algorithm in Ruby on Rails 2.1.0 through 2.2.2, and 2.3.x before 2.3.4, leaks information about the complexity of message-digest signature verification in the cookie store, which might allow remote attackers to forge a digest via multiple attempts.

VendorProductVersions

n/a

n/a

affected
n/a

References

36600
third-party-advisory
x_refsource_SECUNIA
37427
vdb-entry
x_refsource_BID
ADV-2009-2544
vdb-entry
x_refsource_VUPEN
DSA-2260
vendor-advisory
x_refsource_DEBIAN
SUSE-SR:2009:017
vendor-advisory
x_refsource_SUSE

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now