PT-2023-8903 · Rack+6 · Rack+6
CVE-2022-44572
·
Publicado
2023-01-18
·
Atualizado
2026-03-13
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Rack versions 2.0.0 through 2.0.9.1
Rack versions 2.1.0 through 2.1.4.1
Rack versions 2.2.0 through 2.2.4.0
Rack versions 3.0.0 through 3.0.0.0
Description
A denial of service vulnerability in the multipart parsing component of Rack could allow an attacker to craft input that can cause RFC2183 multipart boundary parsing in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that parse multipart posts using Rack are impacted.
Recommendations
For Rack versions 2.0.0 through 2.0.9.1, update to version 2.0.9.2 or apply the patch 2-0-Forbid-control-characters-in-attributes.patch.
For Rack versions 2.1.0 through 2.1.4.1, update to version 2.1.4.2 or apply the patch 2-1-Forbid-control-characters-in-attributes.patch.
For Rack versions 2.2.0 through 2.2.4.0, update to version 2.2.4.1 or apply the patch 2-2-Forbid-control-characters-in-attributes.patch.
For Rack versions 3.0.0 through 3.0.0.0, update to version 3.0.0.1 or apply the patch 3-0-Forbid-control-characters-in-attributes.patch.
Exploit
Correção
DoS
Resource Exhaustion
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Astra Linux
Linuxmint
Rack
Red Os
Rocky Linux
Suse
Ubuntu