Show plain JSON{"acknowledgement": "Red Hat would like to thank Ruby on Rails project for reporting this issue. Upstream acknowledges Aaron Neyer as the original reporter.", "affected_release": [{"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "cfme-0:5.4.0.5-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "cfme-gemset-0:5.4.0.5-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "cfme-vnc-plugin-0:1.0.0-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "libdnet-0:1.12-11.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "lshw-0:B.02.16-4.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "netapp-manageability-sdk-0:4.0P1-3.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "open-vm-tools-0:9.2.3-5.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "prince-0:9.0r2-4.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "pyliblzma-0:0.5.3-7.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-bcrypt-ruby-0:3.0.1-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-eventmachine-0:1.0.7-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-ffi-0:1.9.8-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-io-extra-0:1.2.8-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-json-0:1.8.2-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-nokogiri-0:1.5.11-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-pg-0:0.12.2-9.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-psych-0:2.0.13-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-qpid_messaging-0:0.20.2-5.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-therubyracer-0:0.11.0-5.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "ruby200-rubygem-thin-0:1.3.1-9.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "sneakernet_ca-0:0.1-2.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}, {"advisory": "RHBA-2015:1100", "cpe": "cpe:/a:redhat:cloudforms_managementengine:5::el6", "package": "wmi-0:1.3.14-1.el6cf", "product_name": "CloudForms Management Engine 5.4", "release_date": "2015-06-16T00:00:00Z"}], "bugzilla": {"description": "rubygem-actionmailer: email address processing DoS", "id": "1013913", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=1013913"}, "csaw": false, "cvss": {"cvss_base_score": "5.0", "cvss_scoring_vector": "AV:N/AC:L/Au:N/C:N/I:N/A:P", "status": "verified"}, "cwe": "CWE-134", "details": ["Multiple format string vulnerabilities in log_subscriber.rb files in the log subscriber component in Action Mailer in Ruby on Rails 3.x before 3.2.15 allow remote attackers to cause a denial of service via a crafted e-mail address that is improperly handled during construction of a log message."], "name": "CVE-2013-4389", "package_state": [{"cpe": "cpe:/a:redhat:openshift:1", "fix_state": "Will not fix", "package_name": "ruby193-rubygem-actionmailer", "product_name": "OpenShift Enterprise 1"}, {"cpe": "cpe:/a:redhat:openstack:3", "fix_state": "Will not fix", "package_name": "ruby193-rubygem-actionmailer", "product_name": "Red Hat OpenStack Platform 3"}, {"cpe": "cpe:/a:redhat:openstack:4", "fix_state": "Will not fix", "package_name": "ruby193-rubygem-actionmailer", "product_name": "Red Hat OpenStack Platform 4"}, {"cpe": "cpe:/a:redhat:satellite:6", "fix_state": "Will not fix", "package_name": "ruby193-rubygem-actionmailer", "product_name": "Red Hat Satellite 6"}, {"cpe": "cpe:/a:redhat:rhel_software_collections:1", "fix_state": "Will not fix", "package_name": "ruby193-rubygem-actionmailer", "product_name": "Red Hat Software Collections"}, {"cpe": "cpe:/a:rhel_sam:1", "fix_state": "Will not fix", "package_name": "ruby193-rubygem-actionmailer", "product_name": "Red Hat Subscription Asset Manager"}, {"cpe": "cpe:/a:rhel_sam:1", "fix_state": "Not affected", "package_name": "rubygem-actionmailer", "product_name": "Red Hat Subscription Asset Manager"}], "public_date": "2013-10-16T00:00:00Z", "references": ["https://www.cve.org/CVERecord?id=CVE-2013-4389\nhttps://nvd.nist.gov/vuln/detail/CVE-2013-4389"], "statement": "Red Hat Product Security has rated this issue as having Low security impact. This issue is not currently planned to be addressed in future updates. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.\nThis issue did not affect the versions of rubygem-actionmailer as shipped with Red Hat Subscription Asset Manager 1 as they do not include support for sending email using user supplied addresses.", "threat_severity": "Low"}