U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2013-0156

Change History

Modified Analysis by NIST 12/06/2018 2:27:04 PM

Action Type Old Value New Value
Added CPE Configuration

								
							
							
						
OR
     *cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
     *cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
Changed CPE Configuration
OR
     *cpe:2.3:a:rubyonrails:rails:1.2.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.5.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.5.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.5.6:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.5.7:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.6.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.6.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.7.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.8.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.8.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.3:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.9.4.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.10.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.10.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.11.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.11.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.12.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.12.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.13.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.13.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.14.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.14.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.14.3:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:0.14.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.0.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.3:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.1.6:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.3:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.2.6:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:1.9.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.0:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.0:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.0.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.1.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.1.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.2.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.3:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.9:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.10:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.11:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.12:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:2.3.13:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* versions up to (including) 2.3.14
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta3:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:beta4:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:rc:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.0:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.1:pre:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.2:pre:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.3:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.4:rc:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.4:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.5:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.6:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.7:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc3:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.8:rc4:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc3:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc4:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.9:rc5:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.10:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.10:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.11:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.12:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.12:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.13:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.13:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.14:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.16:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.0.17:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* versions up to (including) 3.0.18
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:beta1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc3:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc4:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc5:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc6:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc7:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.0:rc8:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.1:rc3:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.2:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.3:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.4:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.5:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.6:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.7:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.1.8:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* versions up to (including) 3.1.9
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.0:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.1:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.2:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.2:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.3:rc2:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.4:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.4:rc1:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.5:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.6:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.7:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.8:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:3.2.9:*:*:*:*:*:*:*
     *cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* versions up to (including) 3.2.10
OR
     *cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* versions up to (excluding) 2.3.15
     *cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* versions from (including) 3.0.0 up to (excluding) 3.0.19
     *cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* versions from (including) 3.1.0 up to (excluding) 3.1.10
     *cpe:2.3:a:rubyonrails:ruby_on_rails:*:*:*:*:*:*:*:* versions from (including) 3.2.0 up to (excluding) 3.2.11
Changed Reference Type
http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A No Types Assigned
http://ics-cert.us-cert.gov/advisories/ICSA-13-036-01A Third Party Advisory, US Government Resource
Changed Reference Type
http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html No Types Assigned
http://lists.apple.com/archives/security-announce/2013/Mar/msg00002.html Mailing List, Third Party Advisory
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-0153.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-0153.html Third Party Advisory
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-0154.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-0154.html Third Party Advisory
Changed Reference Type
http://rhn.redhat.com/errata/RHSA-2013-0155.html No Types Assigned
http://rhn.redhat.com/errata/RHSA-2013-0155.html Third Party Advisory
Changed Reference Type
http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/ No Types Assigned
http://weblog.rubyonrails.org/2013/1/28/Rails-3-0-20-and-2-3-16-have-been-released/ Vendor Advisory
Changed Reference Type
http://www.debian.org/security/2013/dsa-2604 No Types Assigned
http://www.debian.org/security/2013/dsa-2604 Third Party Advisory
Changed Reference Type
http://www.fujitsu.com/global/support/software/security/products-f/sw-sv-rcve-ror201301e.html No Types Assigned
http://www.fujitsu.com/global/support/software/security/products-f/sw-sv-rcve-ror201301e.html Third Party Advisory
Changed Reference Type
http://www.insinuator.net/2013/01/rails-yaml/ No Types Assigned
http://www.insinuator.net/2013/01/rails-yaml/ Third Party Advisory
Changed Reference Type
http://www.kb.cert.org/vuls/id/380039 US Government Resource
http://www.kb.cert.org/vuls/id/380039 Third Party Advisory, US Government Resource
Changed Reference Type
http://www.kb.cert.org/vuls/id/628463 US Government Resource
http://www.kb.cert.org/vuls/id/628463 Third Party Advisory, US Government Resource
Changed Reference Type
https://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156 No Types Assigned
https://community.rapid7.com/community/metasploit/blog/2013/01/09/serialization-mischief-in-ruby-land-cve-2013-0156 Third Party Advisory
Changed Reference Type
https://groups.google.com/group/rubyonrails-security/msg/c1432d0f8c70e89d?dmode=source&output=gplain Vendor Advisory
https://groups.google.com/group/rubyonrails-security/msg/c1432d0f8c70e89d?dmode=source&output=gplain Third Party Advisory
Changed Reference Type
https://puppet.com/security/cve/cve-2013-0156 No Types Assigned
https://puppet.com/security/cve/cve-2013-0156 Third Party Advisory