USN-6837-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-6837-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6837-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6837-1
Related
Published
2024-06-17T13:12:32.090085Z
Modified
2024-06-17T13:12:32.090085Z
Summary
ruby-rack vulnerabilities
Details

It was discovered that Rack incorrectly handled Multipart MIME parsing. A remote attacker could possibly use this issue to cause Rack to consume resources, leading to a denial of service. This issue only affected Ubuntu 23.10. (CVE-2023-27530)

It was discovered that Rack incorrectly parsed certain media types. A remote attacker could possibly use this issue to cause Rack to consume resources, leading to a denial of service. (CVE-2024-25126)

It was discovered that Rack incorrectly handled certain Range headers. A remote attacker could possibly use this issue to cause Rack to create large responses, leading to a denial of service. This issue only affected Ubuntu 24.04 LTS. (CVE-2024-26141)

It was discovered that Rack incorrectly handled certain crafted headers. A remote attacker could possibly use this issue to cause Rack to consume resources, leading to a denial of service. This issue only affected Ubuntu 24.04 LTS. (CVE-2024-26146)

References

Affected packages

Ubuntu:23.10 / ruby-rack

Package

Name
ruby-rack
Purl
pkg:deb/ubuntu/ruby-rack@2.2.4-3ubuntu0.2?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.4-3ubuntu0.2

Affected versions

2.*

2.2.4-3
2.2.4-3ubuntu0.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "ruby-rack": "2.2.4-3ubuntu0.2"
        }
    ]
}

Ubuntu:24.04:LTS / ruby-rack

Package

Name
ruby-rack
Purl
pkg:deb/ubuntu/ruby-rack@2.2.7-1ubuntu0.1?arch=src?distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.2.7-1ubuntu0.1

Affected versions

2.*

2.2.4-3
2.2.7-1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "ruby-rack": "2.2.7-1ubuntu0.1"
        }
    ]
}