The http parser in Phusion Passenger 6.0.21 through 6.0.25 before 6.0.26 allows a denial of service during parsing of a request with an invalid HTTP method.
The product uses or accesses a resource that has not been initialized.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Passenger | Phusion | 6.0.21 (including) | 6.0.26 (excluding) |
Passenger | Ubuntu | devel | * |
Passenger | Ubuntu | upstream | * |