Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

Ubuntu 22.04 LTS: USN-5910-1 Critical: Rack Denial Of Service

ubuntu
Calendar Grey March 2, 2023
Scroller Ubuntu
Several vulnerabilities fixed in Ruby Rack affecting various Ubuntu releases. Guidance for updates provided.
Several security issues were fixed in Rack.

Summary

Several security issues were fixed in Rack.

Software Description:

- ruby-rack: modular Ruby webserver interface

Details:

It was discovered that Rack did not properly structure regular expressions

in some of its parsing components, which could result in uncontrolled

resource consumption if an application using Rack received specially

crafted input. A remote attacker could possibly use this issue to cause a

denial of service. (CVE-2022-44570, CVE-2022-44571)

It was discovered that Rack did not properly structure regular expressions

in its multipart parsing component, which could result in uncontrolled

resource consumption if an application using Rack to parse multipart posts

received specially crafted input. A remote attacker could possibly use

this issue to cause a denial of service. This issue was only fixed in

Ubuntu 20.04 ESM and Ubuntu 22.04 ESM. (CVE-2022-44572)

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS:
   ruby-rack                       2.1.4-5ubuntu1+esm3

Ubuntu 20.04 LTS:
   ruby-rack                       2.0.7-2ubuntu0.1+esm3

Ubuntu 18.04 LTS:
   ruby-rack                       1.6.4-4ubuntu0.2+esm4

Ubuntu 16.04 ESM:
   ruby-rack                       1.6.4-3ubuntu0.2+esm4

Ubuntu 14.04 ESM:
   ruby-rack                       1.5.2-3+deb8u3ubuntu1~esm6

After a standard system update you need to restart any applications using
Rack to make all the necessary changes.

References

  https://ubuntu.com/security/notices/USN-5910-1

  CVE-2022-44570, CVE-2022-44571, CVE-2022-44572

Severity
critical
Lowest
Low
Medium
High
Critical

March 02, 2023

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.