LWN.net Logo

rubygem-rack: denial of service

Package(s):rubygem-rack CVE #(s):CVE-2011-5036
Created:January 17, 2012 Updated:March 6, 2012
Description: From the CVE entry:

Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.

Alerts:
Fedora FEDORA-2012-0166 2012-01-07
Fedora FEDORA-2012-0233 2012-01-07
Gentoo 201203-05 2012-03-05

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds