Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2022-44570

Опубликовано: 09 фев. 2023
Источник: ubuntu
Приоритет: medium
CVSS3: 7.5

Описание

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.

РелизСтатусПримечание
bionic

ignored

end of standard support, was needed
devel

not-affected

2.2.7-1
esm-apps/bionic

released

1.6.4-4ubuntu0.2+esm4
esm-apps/focal

released

2.0.7-2ubuntu0.1+esm3
esm-apps/jammy

released

2.1.4-5ubuntu1+esm3
esm-apps/xenial

released

1.6.4-3ubuntu0.2+esm4
esm-infra-legacy/trusty

not-affected

1.5.2-3+deb8u3ubuntu1~esm6
focal

ignored

end of standard support, was needed
jammy

released

2.1.4-5ubuntu1.1
kinetic

ignored

end of life, was needed

Показывать по

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
redhat
больше 2 лет назад

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.

CVSS3: 7.5
nvd
больше 2 лет назад

A denial of service vulnerability in the Range header parsing component of Rack >= 1.5.0. A Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted.

CVSS3: 7.5
debian
больше 2 лет назад

A denial of service vulnerability in the Range header parsing componen ...

CVSS3: 7.5
github
больше 2 лет назад

Denial of service via header parsing in Rack

CVSS3: 7.5
fstec
больше 2 лет назад

Уязвимость компонента анализа заголовка Range модульного интерфейса между веб-серверами и веб-приложениями Rack, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3