Lucene search

K
ubuntuUbuntuUSN-5910-1
HistoryMar 02, 2023 - 12:00 a.m.

Rack vulnerabilities

2023-03-0200:00:00
ubuntu.com
49
ubuntu
rack
denial of service
cve-2022-44570
cve-2022-44571
cve-2022-44572
regular expressions
resource consumption
multipart parsing

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.002

Percentile

52.1%

Releases

  • Ubuntu 22.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 18.04 ESM
  • Ubuntu 16.04 ESM
  • Ubuntu 14.04 ESM

Packages

  • ruby-rack - modular Ruby webserver interface

Details

It was discovered that Rack did not properly structure regular expressions
in some of its parsing components, which could result in uncontrolled
resource consumption if an application using Rack received specially
crafted input. A remote attacker could possibly use this issue to cause a
denial of service. (CVE-2022-44570, CVE-2022-44571)

It was discovered that Rack did not properly structure regular expressions
in its multipart parsing component, which could result in uncontrolled
resource consumption if an application using Rack to parse multipart posts
received specially crafted input. A remote attacker could possibly use
this issue to cause a denial of service. This issue was only fixed in
Ubuntu 20.04 ESM and Ubuntu 22.04 ESM. (CVE-2022-44572)

OSVersionArchitecturePackageVersionFilename
Ubuntu22.04noarchruby-rack<Β 2.1.4-5ubuntu1+esm3UNKNOWN
Ubuntu22.04noarchruby-rack<Β 2.1.4-5ubuntu1UNKNOWN
Ubuntu20.04noarchruby-rack<Β 2.0.7-2ubuntu0.1+esm3UNKNOWN
Ubuntu20.04noarchruby-rack<Β 2.0.7-2ubuntu0.1UNKNOWN
Ubuntu18.04noarchruby-rack<Β 1.6.4-4ubuntu0.2+esm4UNKNOWN
Ubuntu18.04noarchruby-rack<Β 1.6.4-4ubuntu0.2UNKNOWN
Ubuntu16.04noarchruby-rack<Β 1.6.4-3ubuntu0.2+esm4UNKNOWN
Ubuntu16.04noarchruby-rack<Β 1.6.4-3ubuntu0.2UNKNOWN
Ubuntu14.04noarchruby-rack<Β 1.5.2-3+deb8u3ubuntu1~esm6UNKNOWN
Ubuntu14.04noarchlibrack-ruby<Β 1.5.2-1UNKNOWN
Rows per page:
1-10 of 131

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.002

Percentile

52.1%