CVE Vulnerabilities

CVE-2012-6109

Published: Mar 01, 2013 | Modified: Feb 13, 2023
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW

lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.

Affected Software

Name Vendor Start Version End Version
Rack Rack_project * 1.1.3 (including)
Rack Rack_project 0.1 (including) 0.1 (including)
Rack Rack_project 0.2 (including) 0.2 (including)
Rack Rack_project 0.3 (including) 0.3 (including)
Rack Rack_project 0.4 (including) 0.4 (including)
Rack Rack_project 0.9 (including) 0.9 (including)
Rack Rack_project 0.9.1 (including) 0.9.1 (including)
Rack Rack_project 1.0.0 (including) 1.0.0 (including)
Rack Rack_project 1.0.1 (including) 1.0.1 (including)
Rack Rack_project 1.1.0 (including) 1.1.0 (including)
Rack Rack_project 1.1.2 (including) 1.1.2 (including)
CloudForms for RHEL 6 RedHat rubygem-activesupport-1:3.0.10-10.el6cf *
CloudForms for RHEL 6 RedHat rubygem-delayed_job-0:2.1.4-3.el6cf *
CloudForms for RHEL 6 RedHat rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf *
CloudForms for RHEL 6 RedHat rubygem-rack-1:1.3.0-3.el6cf *
CloudForms for RHEL 6 RedHat rubygem-rails_warden-0:0.5.5-2.el6cf *
CloudForms for RHEL 6 RedHat rubygem-rdoc-0:3.8-6.el6cf *
CloudForms for RHEL 6 RedHat rubygem-rspec-rails-0:2.6.1-7.el6cf *
CloudForms for RHEL 6 RedHat rubygem-ruby_parser-0:2.0.4-6.el6cf *
CloudForms for RHEL 6 RedHat rubygem-shoulda-0:2.11.3-5.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat apache-commons-codec-0:1.7-2.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat apache-mime4j-0:0.6-4_redhat_1.ep6.el6.1 *
Red Hat Subscription Asset Manager 1.2 RedHat candlepin-0:0.7.23-1.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat elasticsearch-0:0.19.9-5.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-0:1.2.1-15h.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-certs-tools-0:1.2.1-1h.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-cli-0:1.2.1-12h.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-configure-0:1.2.3-3h.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat katello-selinux-0:1.2.1-2h.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat lucene3-0:3.6.1-10h.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat puppet-0:2.6.17-2.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat quartz-0:2.1.5-4.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-activesupport-1:3.0.10-10.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-apipie-rails-0:0.0.12-2.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-ldap_fluff-0:0.1.3-1.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-mail-0:2.3.0-3.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-rack-1:1.3.0-3.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat rubygem-ruby_parser-0:2.0.4-6.el6cf *
Red Hat Subscription Asset Manager 1.2 RedHat sigar-0:1.6.5-0.12.git58097d9h.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat snappy-java-0:1.0.4-2.el6_3 *
Red Hat Subscription Asset Manager 1.2 RedHat thumbslug-0:0.0.28-1.el6_3 *
Ruby-rack Ubuntu devel *
Ruby-rack Ubuntu precise *
Ruby-rack Ubuntu quantal *
Ruby-rack Ubuntu raring *
Ruby-rack Ubuntu saucy *
Ruby-rack Ubuntu trusty *
Ruby-rack Ubuntu upstream *
Ruby-rack Ubuntu utopic *
Ruby-rack Ubuntu vivid *
Ruby-rack Ubuntu wily *
Ruby-rack Ubuntu xenial *
Ruby-rack Ubuntu yakkety *
Ruby-rack Ubuntu zesty *

References