Denial of Service Vulnerability in Rack by Ruby
CVE-2013-0183

Currently unrated

Key Information:

Status
Vendor
CVE Published:
1 March 2013

What is CVE-2013-0183?

A vulnerability in Rack's multipart parser prior to version 1.3.8 and 1.4.3 allows remote attackers to exploit a denial of service condition. By sending a crafted Multipart HTTP packet containing excessively long strings, attackers can lead to memory consumption issues, resulting in out-of-memory exceptions and potentially causing the application to crash.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2013-0183 : Denial of Service Vulnerability in Rack by Ruby