Ruby on Rails 2.3.9 and 3.0.0 does not properly handle nested attributes,
which allows remote attackers to modify arbitrary records by changing the
names of parameters for form inputs.
2x YES, added to request.
This issue was resolved and addressed in
GLSA 201412-28 at http://security.gentoo.org/glsa/glsa-201412-28.xml
by GLSA coordinator Sean Amoss (ackle).