5
CVSSv2

CVE-2013-0183

Published: 01/03/2013 Updated: 13/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

multipart/parser.rb in Rack 1.3.x prior to 1.3.8 and 1.4.x prior to 1.4.3 allows remote malicious users to cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rack project rack 1.3.1

rack project rack 1.3.7

rack project rack 1.3.2

rack project rack 1.3.5

rack project rack 1.3.6

rack project rack 1.3.0

rack project rack 1.3.4

rack project rack 1.3.3

rack project rack 1.4.2

rack project rack 1.4.0

rack project rack 1.4.1

Vendor Advisories

Synopsis Important: Subscription Asset Manager 12 update Type/Severity Security Advisory: Important Topic Red Hat Subscription Asset Manager 12, which fixes several securityissues, multiple bugs, and adds various enhancements, is now availableThe Red Hat Security Response Team has rated this update as ha ...
Debian Bug report logs - #700173 ruby-rack: CVE-2013-0262: Path sanitization information disclosure Package: src:ruby-rack; Maintainer for src:ruby-rack is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 9 Feb 2013 ...
Debian Bug report logs - #698440 ruby-rack: CVE-2012-6109 CVE-2013-0184 CVE-2013-0183 Package: ruby-rack; Maintainer for ruby-rack is Debian Ruby Extras Maintainers <pkg-ruby-extras-maintainers@listsaliothdebianorg>; Source for ruby-rack is src:ruby-rack (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@inutil ...
Several vulnerabilities were discovered in Rack, a modular Ruby webserver interface The Common Vulnerabilites and Exposures project identifies the following vulnerabilities: CVE-2011-5036 Rack computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers ...