VDB
Sign up
MEDIUM

GHSA-rg5m-3fqp-6px8

actionmailer email address processing causes Denial of service

Quick fix

GHSA-rg5m-3fqp-6px8 — actionmailer: upgrade to the fixed version with the command below.

bundle update actionmailer

Details

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

Are you affected?

Enter the version of the package you're using.

Affected packages

RubyGems/actionmailer
Introduced in: 3.0.0Fixed in: 3.2.15
Fixbundle update actionmailer

References