CVE Vulnerabilities

CVE-2012-6109

Published: Mar 01, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V2
4.3 MODERATE
AV:N/AC:M/Au:N/C:N/I:N/A:P
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.

Affected Software

NameVendorStart VersionEnd Version
RackRack_project*1.1.3 (including)
RackRack_project0.1 (including)0.1 (including)
RackRack_project0.2 (including)0.2 (including)
RackRack_project0.3 (including)0.3 (including)
RackRack_project0.4 (including)0.4 (including)
RackRack_project0.9 (including)0.9 (including)
RackRack_project0.9.1 (including)0.9.1 (including)
RackRack_project1.0.0 (including)1.0.0 (including)
RackRack_project1.0.1 (including)1.0.1 (including)
RackRack_project1.1.0 (including)1.1.0 (including)
RackRack_project1.1.2 (including)1.1.2 (including)
CloudForms for RHEL 6RedHatrubygem-activesupport-1:3.0.10-10.el6cf*
CloudForms for RHEL 6RedHatrubygem-delayed_job-0:2.1.4-3.el6cf*
CloudForms for RHEL 6RedHatrubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf*
CloudForms for RHEL 6RedHatrubygem-rack-1:1.3.0-3.el6cf*
CloudForms for RHEL 6RedHatrubygem-rails_warden-0:0.5.5-2.el6cf*
CloudForms for RHEL 6RedHatrubygem-rdoc-0:3.8-6.el6cf*
CloudForms for RHEL 6RedHatrubygem-rspec-rails-0:2.6.1-7.el6cf*
CloudForms for RHEL 6RedHatrubygem-ruby_parser-0:2.0.4-6.el6cf*
CloudForms for RHEL 6RedHatrubygem-shoulda-0:2.11.3-5.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatapache-commons-codec-0:1.7-2.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatapache-mime4j-0:0.6-4_redhat_1.ep6.el6.1*
Red Hat Subscription Asset Manager 1.2RedHatcandlepin-0:0.7.23-1.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatelasticsearch-0:0.19.9-5.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-0:1.2.1-15h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-certs-tools-0:1.2.1-1h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-cli-0:1.2.1-12h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-configure-0:1.2.3-3h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatkatello-selinux-0:1.2.1-2h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatlucene3-0:3.6.1-10h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatpuppet-0:2.6.17-2.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatquartz-0:2.1.5-4.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-activesupport-1:3.0.10-10.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-apipie-rails-0:0.0.12-2.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-ldap_fluff-0:0.1.3-1.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-mail-0:2.3.0-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-rack-1:1.3.0-3.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatrubygem-ruby_parser-0:2.0.4-6.el6cf*
Red Hat Subscription Asset Manager 1.2RedHatsigar-0:1.6.5-0.12.git58097d9h.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatsnappy-java-0:1.0.4-2.el6_3*
Red Hat Subscription Asset Manager 1.2RedHatthumbslug-0:0.0.28-1.el6_3*
Ruby-rackUbuntudevel*
Ruby-rackUbuntuesm-apps/xenial*
Ruby-rackUbuntuesm-infra-legacy/trusty*
Ruby-rackUbuntuprecise*
Ruby-rackUbuntuquantal*
Ruby-rackUbunturaring*
Ruby-rackUbuntusaucy*
Ruby-rackUbuntutrusty*
Ruby-rackUbuntutrusty/esm*
Ruby-rackUbuntuupstream*
Ruby-rackUbuntuutopic*
Ruby-rackUbuntuvivid*
Ruby-rackUbuntuwily*
Ruby-rackUbuntuxenial*
Ruby-rackUbuntuyakkety*
Ruby-rackUbuntuzesty*

References