4.3
CVSSv2

CVE-2012-6109

Published: 01/03/2013 Updated: 13/02/2023
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P

Vulnerability Summary

lib/rack/multipart.rb in Rack prior to 1.1.4, 1.2.x prior to 1.2.6, 1.3.x prior to 1.3.7, and 1.4.x prior to 1.4.2 uses an incorrect regular expression, which allows remote malicious users to cause a denial of service (infinite loop) via a crafted Content-Disposion header.

Vulnerable Product Search on Vulmon Subscribe to Product

rack project rack 0.4

rack project rack 1.1.2

rack project rack 0.2

rack project rack 0.1

rack project rack 1.1.0

rack project rack 0.9

rack project rack 1.0.1

rack project rack

rack project rack 0.3

rack project rack 0.9.1

rack project rack 1.0.0

rack project rack 1.2.3

rack project rack 1.2.0

rack project rack 1.2.1

rack project rack 1.2.4

rack project rack 1.2.2

rack project rack 1.3.1

rack project rack 1.3.2

rack project rack 1.3.5

rack project rack 1.3.6

rack project rack 1.3.0

rack project rack 1.3.4

rack project rack 1.3.3

rack project rack 1.4.0

rack project rack 1.4.1

Vendor Advisories

Synopsis Important: Subscription Asset Manager 12 update Type/Severity Security Advisory: Important Topic Red Hat Subscription Asset Manager 12, which fixes several securityissues, multiple bugs, and adds various enhancements, is now availableThe Red Hat Security Response Team has rated this update as ha ...
Debian Bug report logs - #700173 ruby-rack: CVE-2013-0262: Path sanitization information disclosure Package: src:ruby-rack; Maintainer for src:ruby-rack is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 9 Feb 2013 ...
Debian Bug report logs - #698440 ruby-rack: CVE-2012-6109 CVE-2013-0184 CVE-2013-0183 Package: ruby-rack; Maintainer for ruby-rack is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for ruby-rack is src:ruby-rack (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutil ...