Lucene search

K
ubuntucveUbuntu.comUB:CVE-2022-44571
HistoryFeb 09, 2023 - 12:00 a.m.

CVE-2022-44571

2023-02-0900:00:00
ubuntu.com
ubuntu.com
16
denial of service
vulnerability
rack
content-disposition
parsing
version
impact
application

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

41.6%

There is a denial of service vulnerability in the Content-Disposition
parsingcomponent of Rack fixed in 2.0.9.2, 2.1.4.2, 2.2.4.1, 3.0.0.1. This
could allow an attacker to craft an input that can cause
Content-Disposition header parsing in Rackto take an unexpected amount of
time, possibly resulting in a denial ofservice attack vector. This header
is used typically used in multipartparsing. Any applications that parse
multipart posts using Rack (virtuallyall Rails applications) are impacted.

Bugs

OSVersionArchitecturePackageVersionFilename
ubuntu18.04noarchruby-rack< 1.6.4-4ubuntu0.2+esm4UNKNOWN
ubuntu20.04noarchruby-rack< 2.0.7-2ubuntu0.1+esm3UNKNOWN
ubuntu22.04noarchruby-rack< 2.1.4-5ubuntu1+esm3UNKNOWN
ubuntu14.04noarchruby-rack< 1.5.2-3+deb8u3ubuntu1~esm6UNKNOWN
ubuntu16.04noarchruby-rack< 1.6.4-3ubuntu0.2+esm4UNKNOWN

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

0.001 Low

EPSS

Percentile

41.6%