CVE-2013-4389

EPSS 1.3%

actionmailer email address processing causes Denial of service

Published: 10/24/2017Modified: 12/6/2024
Also known as:GHSA-rg5m-3fqp-6px8

Description

Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message.

Affected packages (3)

References (10)