Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2015-3225

Опубликовано: 16 июн. 2015
Источник: redhat
CVSS2: 4.3
EPSS Средний

Описание

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

A flaw was found in a way Rack processed parameters of incoming requests. An attacker could use this flaw to send a crafted request that would cause an application using Rack to crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
CloudForms Management Engine 5ruby193-rubygem-rackWill not fix
OpenStack Foremanrubygem-rackWill not fix
Red Hat Enterprise MRG 2rubygem-rackWill not fix
Red Hat OpenShift Enterprise 2rubygem-rackWill not fix
Red Hat Software Collectionsrh-ror41-rubygem-rackWill not fix
Red Hat Software Collectionsror40-rubygem-rackWill not fix
Red Hat Software Collectionsruby193-rubygem-rackWill not fix
Red Hat Subscription Asset Managerrubygem-rackWill not fix
Red Hat Enterprise Linux 7pcsFixedRHSA-2015:229019.11.2015
Red Hat Satellite 6.3 for RHEL 7createrepo_cFixedRHBA-2018:033721.02.2018

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=1232292rubygem-rack: Potential Denial of Service Vulnerability in Rack normalize_params()

EPSS

Процентиль: 94%
0.1408
Средний

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

nvd
больше 10 лет назад

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.

debian
больше 10 лет назад

lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used ...

suse-cvrf
около 10 лет назад

Security update for rubygem-rack-1_4

suse-cvrf
больше 10 лет назад

Security update for rubygem-rack

EPSS

Процентиль: 94%
0.1408
Средний

4.3 Medium

CVSS2

Уязвимость CVE-2015-3225