Описание
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
Пакеты
| Пакет | Статус | Версия исправления | Релиз | Тип |
|---|---|---|---|---|
| passenger | fixed | 6.0.26+ds-1 | package | |
| passenger | not-affected | bookworm | package | |
| passenger | not-affected | bullseye | package |
Примечания
https://blog.phusion.nl/2025/02/19/passenger-6-0-26/
Introduced with: https://github.com/phusion/passenger/commit/f51fc490472882b236c52d708d605a1961dacb18 (release-6.0.21)
Fixed by: https://github.com/phusion/passenger/commit/bb15591646687064ab2d578d5f9660b2a4168017 (release-6.0.26)
EPSS
Связанные уязвимости
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
EPSS