CVE-2011-5036: Medium severity rack-project rack vulnerability
Rack before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2011-5036?
CVE-2011-5036 has a moderate severity rating due to its potential for denial of service attacks.
How do I fix CVE-2011-5036?
To fix CVE-2011-5036, upgrade Rack to version 1.1.3, 1.2.5, or 1.3.6 or later.
What types of attacks does CVE-2011-5036 enable?
CVE-2011-5036 enables remote attackers to perform denial of service attacks through crafted form parameters.
Which versions of Rack are affected by CVE-2011-5036?
CVE-2011-5036 affects Rack versions before 1.1.3, 1.2.x before 1.2.5, and 1.3.x before 1.3.6.
Is there a known exploit for CVE-2011-5036?
While there are no public exploits specifically documented for CVE-2011-5036, its vulnerability can be exploited to exhaust server CPU resources.