Bugzilla – Bug 1207597
VUL-0: CVE-2022-44570: rubygem-rack: denial of service in Content-Disposition parsing
Last modified: 2024-05-03 10:44:27 UTC
rh#2164719 Carefully crafted input can cause the Range header parsing component in Rack to take an unexpected amount of time, possibly resulting in a denial of service attack vector. Any applications that deal with Range requests (such as streaming applications, or applications that serve files) may be impacted. Upstream fix: https://github.com/rack/rack/commit/7a9d76a7850455a5ef9403203ea757ed110e7806 References: https://bugzilla.redhat.com/show_bug.cgi?id=2164719 http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-44570
Affected: - SUSE:SLE-12:Update - SUSE:SLE-15:Update
Will submit for 15,12/rubygem-rack.
Packages submitted. I believe all fixed.
SUSE-SU-2023:0276-1: An update that fixes three vulnerabilities is now available. Category: security (moderate) Bug References: 1207596,1207597,1207599 CVE References: CVE-2022-44570,CVE-2022-44571,CVE-2022-44572 JIRA References: Sources used: openSUSE Leap 15.4 (src): rubygem-rack-2.0.8-150000.3.12.1 SUSE Linux Enterprise High Availability 15-SP4 (src): rubygem-rack-2.0.8-150000.3.12.1 SUSE Linux Enterprise High Availability 15-SP3 (src): rubygem-rack-2.0.8-150000.3.12.1 SUSE Linux Enterprise High Availability 15-SP2 (src): rubygem-rack-2.0.8-150000.3.12.1 SUSE Linux Enterprise High Availability 15-SP1 (src): rubygem-rack-2.0.8-150000.3.12.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0649-1: An update that solves two vulnerabilities can now be installed. Category: security (moderate) Bug References: 1207597, 1207599 CVE References: CVE-2022-44570, CVE-2022-44571 Sources used: SUSE OpenStack Cloud Crowbar 8 (src): rubygem-rack-1.6.13-3.16.1 SUSE OpenStack Cloud Crowbar 9 (src): rubygem-rack-1.6.13-3.16.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done, closing