Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 428
Alerts This Week
Warning Icon 1 428

Ubuntu 22.04 & 20.04: USN-7031-2 critical: Puma header overwrite

ubuntu
Calendar Grey September 24, 2024
Scroller Ubuntu
The Ubuntu Security Notice USN-7031-2 addresses a vulnerability concerning Puma's header handling, impacting several distributions along with steps for corrective measures.
Puma could be made to overwrite headers if it received specially crafted network traffic.

Summary

Puma could be made to overwrite headers if it received specially crafted

network traffic.

Software Description:

- puma: threaded HTTP 1.1 server for Ruby/Rack applications

Details:

USN-7031-1 fixed CVE-2024-45614 in Puma for Ubuntu 24.04 LTS.

This update fixes the CVE for Ubuntu 22.04 LTS and Ubuntu 20.04 LTS.

Original advisory details:

It was discovered that Puma incorrectly handled parsing certain headers.

A remote attacker could possibly use this issue to overwrite header values

set by intermediate proxies by providing duplicate headers containing

underscore characters.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 22.04 LTS
puma 5.5.2-2ubuntu2+esm2
Available with Ubuntu Pro

Ubuntu 20.04 LTS
puma 3.12.4-1ubuntu2+esm2
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-7031-2

https://ubuntu.com/security/notices/USN-7031-1

CVE-2024-45614

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-7031-2

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.