CVE-2013-0263: Medium severity rack-project rack vulnerability
James Tucker (raggi) reports:
CVE: CVE-2013-0263 Software: Rack (rack.github.com) Type of vulnerability: Timing attack, leading to potential RCE
Vulnerable code: https://github.com/rack/rack/blob/master/lib/rack/session/cookie.rb#L149 Patch: https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07 https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11
Versions affected: All prior versions. Versions fixed: 1.1.6, 1.2.8, 1.3.10, 1.4.5, 1.5.2 Reporter: Ben Murphy
Reference: http://seclists.org/oss-sec/2013/q1/271
Other sources
Rack::Session::Cookie in Rack 1.5.x before 1.5.2, 1.4.x before 1.4.5, 1.3.x before 1.3.10, 1.2.x before 1.2.8, and 1.1.x before 1.1.6 allows remote attackers to guess the session cookie, gain privileges, and execute arbitrary code via a timing attack involving an HMAC comparison function that does not run in constant time.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2013-0263?
CVE-2013-0263 is classified as a timing attack vulnerability with the potential for remote code execution.
How do I fix CVE-2013-0263?
To mitigate CVE-2013-0263, upgrade to the corrected versions of affected software as listed in the official advisory.
Which software versions are affected by CVE-2013-0263?
CVE-2013-0263 affects specific versions of Rack and associated packages including specific versions of candlepin, katello, and others.
What types of vulnerabilities are associated with CVE-2013-0263?
CVE-2013-0263 is associated with a timing attack that may expose sensitive information or allow unauthorized access.
Is CVE-2013-0263 included in any security patches?
Yes, CVE-2013-0263 is addressed in specific security updates provided by Red Hat as part of their advisory.