Sha256: 5282b067d52472104c233b3f282dd18ce2442b4b4776c2e6efed2441e9771760

Contents?: true

Size: 635 Bytes

Versions: 1

Compression:

Stored size: 635 Bytes

Contents

---
gem: rack
cve: 2012-6109
osvdb: 89317
url: https://nvd.nist.gov/vuln/detail/CVE-2012-6109
title: |
  Rack Regular Expressions Engine Content-Disposition Header Parsing Infinite Loop Remote DoS
date: 2012-05-04

description: |
  Rack contains a flaw in the Regular Expressions Engine that may allow a remote
  denial of service. The issue is triggered when parsing context-disposition
  headers. With a specially crafted header, a remote attacker can cause an
  infinite loop, which will result in a loss of availability for the webserver.

cvss_v2: 4.3
patched_versions:
  - "~> 1.1.4"
  - "~> 1.2.6"
  - "~> 1.3.7"
  - ">= 1.4.2"

Version data entries

1 entries across 1 versions & 1 rubygems

Version Path
bundler-audit-0.7.0.1 data/ruby-advisory-db/gems/rack/CVE-2012-6109.yml