Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

Debian: DSA-2783-1 Critical: Librack-Ruby Remote Access Denial Of Service

debian
Calendar Grey October 21, 2013
Debian Logo
Debian Security Advisory DSA-2784-1 highlights multiple vulnerabilities found in libyaml-ruby.
Several vulnerabilities were discovered in Rack, a modular Ruby webserver interface

Summary

CVE-2011-5036

Rack computes hash values for form parameters without restricting
the ability to trigger hash collisions predictably, which allows
remote attackers to cause a denial of service (CPU consumption)
by sending many crafted parameters.

CVE-2013-0184

Vulnerability in Rack::Auth::AbstractRequest allows remote
attackers to cause a denial of service via unknown vectors.

CVE-2013-0263

Rack::Session::Cookie allows remote attackers to guess the
session cookie, gain privileges, and execute arbitrary code via a
timing attack involving am HMAC comparison function that does not
run in constant time.

For the oldstable distribution (squeeze), these problems have been fixed in
version 1.1.0-4+squeeze1.

The stable, testing and unstable distributions do not contain the
librack-ruby package. They have already been addressed in version
1.4.1-2.1 of the ruby-rack package.

We recommend that you upgrade your librack-ruby packages.

Further information about Debian Security...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: librack-ruby
CVE ID: CVE-2011-5036 CVE-2013-0184 CVE-2013-0263

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here