=========================================================================Ubuntu Security Notice USN-4502-1
September 16, 2020

ruby-websocket-extensions vulnerability
=========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS

Summary:

websocket-extensions could be made to exhaust the server's capacity to
process incoming requests if it received specially crafted requests.

Software Description:
- ruby-websocket-extensions: Generic extension manager for WebSocket
connections

Details:

It was discovered that websocket-extensions does not properly parse
special headers. A remote attacker could use this issue to cause regex
backtracking, resulting in a denial of service. (CVE-2020-7663)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS:
  ruby-websocket-extensions       0.1.2-1+deb9u1build0.20.04.1

Ubuntu 18.04 LTS:
  ruby-websocket-extensions       0.1.2-1+deb9u1build0.18.04.1

Ubuntu 16.04 LTS:
  ruby-websocket-extensions       0.1.2-1+deb9u1build0.16.04.1

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-4502-1
  CVE-2020-7663

Package Information:

https://launchpad.net/ubuntu/+source/ruby-websocket-extensions/0.1.2-1+deb9u1build0.20.04.1

https://launchpad.net/ubuntu/+source/ruby-websocket-extensions/0.1.2-1+deb9u1build0.18.04.1

https://launchpad.net/ubuntu/+source/ruby-websocket-extensions/0.1.2-1+deb9u1build0.16.04.1

Ubuntu 4502-1: websocket-extensions vulnerability

September 16, 2020
websocket-extensions could be made to exhaust the server's capacity to process incoming requests if it received specially crafted requests.

Summary

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 20.04 LTS: ruby-websocket-extensions 0.1.2-1+deb9u1build0.20.04.1 Ubuntu 18.04 LTS: ruby-websocket-extensions 0.1.2-1+deb9u1build0.18.04.1 Ubuntu 16.04 LTS: ruby-websocket-extensions 0.1.2-1+deb9u1build0.16.04.1 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-4502-1

CVE-2020-7663

Severity
September 16, 2020

Package Information

https://launchpad.net/ubuntu/+source/ruby-websocket-extensions/0.1.2-1+deb9u1build0.20.04.1 https://launchpad.net/ubuntu/+source/ruby-websocket-extensions/0.1.2-1+deb9u1build0.18.04.1 https://launchpad.net/ubuntu/+source/ruby-websocket-extensions/0.1.2-1+deb9u1build0.16.04.1

Related News