{"id":"UBUNTU-CVE-2013-0285","details":"The nori gem 2.0.x before 2.0.2, 1.1.x before 1.1.4, and 1.0.x before 1.0.3 for Ruby does not properly restrict casts of string values, which allows remote attackers to conduct object-injection attacks and execute arbitrary code, or cause a denial of service (memory and CPU consumption) involving nested XML entity references, by leveraging Action Pack support for (1) YAML type conversion or (2) Symbol type conversion, a similar vulnerability to CVE-2013-0156.","modified":"2025-07-16T07:17:04.644230Z","published":"2013-04-09T20:55:00Z","withdrawn":"2025-07-18T16:42:49Z","upstream":["CVE-2013-0285"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2013-0285"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2013-0285"}],"affected":[{"package":{"name":"ruby-actionpack-3.2","ecosystem":"Ubuntu:14.04:LTS","purl":"pkg:deb/ubuntu/ruby-actionpack-3.2@3.2.16-3?arch=source&distro=trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.2.16-3"}]}],"versions":["3.2.13-7"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"ruby-actionpack-3.2","binary_version":"3.2.16-3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2013/UBUNTU-CVE-2013-0285.json"}}],"schema_version":"1.7.3","severity":[{"type":"Ubuntu","score":"medium"}]}