Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

Ubuntu 22.04 LTS USN-5896-1 Critical: Rack Remote Execution Risks

ubuntu
Calendar Grey February 27, 2023
Scroller Ubuntu
Numerous critical vulnerabilities identified in Ruby Rack for Ubuntu may enable malicious actors to run arbitrary code or induce service outages.
Several security issues were fixed in Rack.

Summary

Several security issues were fixed in Rack.

Software Description:

- ruby-rack: modular Ruby webserver interface

Details:

It was discovered that Rack was not properly parsing data when processing

multipart POST requests. If a user or automated system were tricked into

sending a specially crafted multipart POST request to an application using

Rack, a remote attacker could possibly use this issue to cause a denial of

service. (CVE-2022-30122)

It was discovered that Rack was not properly escaping untrusted data when

performing logging operations, which could cause shell escaped sequences

to be written to a terminal. If a user or automated system were tricked

into sending a specially crafted request to an application using Rack, a

remote attacker could possibly use this issue to execute arbitrary code in

the machine running the application. (CVE-2022-30123)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
   ruby-rack                       2.1.4-5ubuntu1+esm2

Ubuntu 20.04 LTS:
   ruby-rack                       2.0.7-2ubuntu0.1+esm2

Ubuntu 18.04 LTS:
   ruby-rack                       1.6.4-4ubuntu0.2+esm2

After a standard system update you need to restart any applications using
Rack to make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-5896-1

  CVE-2022-30122, CVE-2022-30123

Severity
critical
Lowest
Low
Medium
High
Critical

February 27, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.