Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Debian DSA-4247-1: Critical Timing Attack Fix in Ruby Rack Protection

debian
Calendar Grey July 16, 2018
Debian Logo
Enhance address handling in response to timing attack flaws within Ruby rack protection system for Debian stable release.
A timing attack was discovered in the function for CSRF token validation of the "Ruby rack protection" framework. For the stable distribution (stretch), this problem has...

Summary

A timing attack was discovered in the function for CSRF token validation
of the "Ruby rack protection" framework.

For the stable distribution (stretch), this problem has been fixed in
version 1.5.3-2+deb9u1.

We recommend that you upgrade your ruby-rack-protection packages.

For the detailed security status of ruby-rack-protection please refer to
its security tracker page at:

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
critical
Lowest
Low
Medium
High
Critical

Package: ruby-rack-protection
CVE ID: CVE-2018-1000119

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here