Back to search
CVE-2013-0263
Published: Feb 8, 2013
Modified: Aug 6, 2024
PUBLISHED
Description
Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
52774
third-party-advisory
x_refsource_SECUNIA
https://groups.google.com/forum/#%21msg/rack-devel/mZsuRonD7G8/DpZIOmMLbOgJ
x_refsource_CONFIRM
https://groups.google.com/forum/#%21msg/rack-devel/RnQxm6i13C4/xfakH81yWvgJ
x_refsource_CONFIRM
https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11
x_refsource_CONFIRM
52033
third-party-advisory
x_refsource_SECUNIA
https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07
x_refsource_CONFIRM
http://rack.github.com/
x_refsource_CONFIRM
52134
third-party-advisory
x_refsource_SECUNIA
https://groups.google.com/d/msg/rack-devel/xKrHVWeNvDM/4ZGA576CnK4J
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=909071
x_refsource_MISC
https://groups.google.com/forum/#%21msg/rack-devel/hz-liLb9fKE/8jvVWU6xYiYJ
x_refsource_CONFIRM
https://groups.google.com/forum/#%21msg/rack-devel/bf937jPZxJM/1s6x95vIhmAJ
x_refsource_CONFIRM
RHSA-2013:0686
vendor-advisory
x_refsource_REDHAT
openSUSE-SU-2013:0462
vendor-advisory
x_refsource_SUSE
https://puppet.com/security/cve/cve-2013-0263
x_refsource_CONFIRM
https://gist.github.com/codahale/f9f3781f7b54985bee94
x_refsource_MISC
https://twitter.com/coda/statuses/299732877745197056
x_refsource_MISC
89939
vdb-entry
x_refsource_OSVDB
DSA-2783
vendor-advisory
x_refsource_DEBIAN
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now