lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Rack | Rack_project | * | 1.1.3 (including) |
Rack | Rack_project | 0.1 (including) | 0.1 (including) |
Rack | Rack_project | 0.2 (including) | 0.2 (including) |
Rack | Rack_project | 0.3 (including) | 0.3 (including) |
Rack | Rack_project | 0.4 (including) | 0.4 (including) |
Rack | Rack_project | 0.9 (including) | 0.9 (including) |
Rack | Rack_project | 0.9.1 (including) | 0.9.1 (including) |
Rack | Rack_project | 1.0.0 (including) | 1.0.0 (including) |
Rack | Rack_project | 1.0.1 (including) | 1.0.1 (including) |
Rack | Rack_project | 1.1.0 (including) | 1.1.0 (including) |
Rack | Rack_project | 1.1.2 (including) | 1.1.2 (including) |
CloudForms for RHEL 6 | RedHat | rubygem-activesupport-1:3.0.10-10.el6cf | * |
CloudForms for RHEL 6 | RedHat | rubygem-delayed_job-0:2.1.4-3.el6cf | * |
CloudForms for RHEL 6 | RedHat | rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf | * |
CloudForms for RHEL 6 | RedHat | rubygem-rack-1:1.3.0-3.el6cf | * |
CloudForms for RHEL 6 | RedHat | rubygem-rails_warden-0:0.5.5-2.el6cf | * |
CloudForms for RHEL 6 | RedHat | rubygem-rdoc-0:3.8-6.el6cf | * |
CloudForms for RHEL 6 | RedHat | rubygem-rspec-rails-0:2.6.1-7.el6cf | * |
CloudForms for RHEL 6 | RedHat | rubygem-ruby_parser-0:2.0.4-6.el6cf | * |
CloudForms for RHEL 6 | RedHat | rubygem-shoulda-0:2.11.3-5.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | apache-commons-codec-0:1.7-2.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | apache-mime4j-0:0.6-4_redhat_1.ep6.el6.1 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | candlepin-0:0.7.23-1.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | elasticsearch-0:0.19.9-5.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | katello-0:1.2.1-15h.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | katello-certs-tools-0:1.2.1-1h.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | katello-cli-0:1.2.1-12h.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | katello-configure-0:1.2.3-3h.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | katello-selinux-0:1.2.1-2h.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | lucene3-0:3.6.1-10h.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | puppet-0:2.6.17-2.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | quartz-0:2.1.5-4.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-activesupport-1:3.0.10-10.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-apipie-rails-0:0.0.12-2.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-ldap_fluff-0:0.1.3-1.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-mail-0:2.3.0-3.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-rack-1:1.3.0-3.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | rubygem-ruby_parser-0:2.0.4-6.el6cf | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | sigar-0:1.6.5-0.12.git58097d9h.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | snappy-java-0:1.0.4-2.el6_3 | * |
Red Hat Subscription Asset Manager 1.2 | RedHat | thumbslug-0:0.0.28-1.el6_3 | * |
Ruby-rack | Ubuntu | devel | * |
Ruby-rack | Ubuntu | precise | * |
Ruby-rack | Ubuntu | quantal | * |
Ruby-rack | Ubuntu | raring | * |
Ruby-rack | Ubuntu | saucy | * |
Ruby-rack | Ubuntu | trusty | * |
Ruby-rack | Ubuntu | upstream | * |
Ruby-rack | Ubuntu | utopic | * |
Ruby-rack | Ubuntu | vivid | * |
Ruby-rack | Ubuntu | wily | * |
Ruby-rack | Ubuntu | xenial | * |
Ruby-rack | Ubuntu | yakkety | * |
Ruby-rack | Ubuntu | zesty | * |