Denial of service vulnerability in Rack library by Rack
CVE-2012-6109

Currently unrated

Key Information:

Status
Vendor
CVE Published:
1 March 2013

What is CVE-2012-6109?

A vulnerability in the Rack library allows remote attackers to exploit an incorrect regular expression implementation in the multipart.rb file. This exploitation can lead to a denial of service by causing an infinite loop, thereby affecting the availability of web applications utilizing this library. The affected versions include prior releases of Rack which fail to adequately validate the Content-Disposition header, allowing crafted input to trigger this state.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2012-6109 : Denial of service vulnerability in Rack library by Rack