CVE-2015-3225: Medium severity rack-project rack vulnerability
Published Jul 26, 2015
·Updated
lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.
Affected Software
10 affected componentsFixes available
rubygems/rack>=1.4.0<1.4.6
1.4.6
rubygems/rack>=1.5.0<1.5.4
1.5.4
rubygems/rack>=1.6.0<1.6.2
1.6.2
Rack Project Rack<=1.5.3
Rack Project Rack=1.6.0
Rack Project Rack=1.6.1
openSUSE openSUSE=13.1
openSUSE openSUSE=13.2
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Remediation
Patch Available
Event History
Jul 26, 2015
CVE Published
via MITRE·10:00 PM
Data Sourced
via MITRE·10:00 PM
Description
Oct 24, 2017
Advisory Published
06:33 PM
Frequently Asked Questions
1
What is the severity of CVE-2015-3225?
CVE-2015-3225 is classified as a moderate severity vulnerability due to its potential to cause denial of service.
2
How do I fix CVE-2015-3225?
To fix CVE-2015-3225, upgrade Rack to version 1.5.4, 1.6.2, or later.
3
What systems are affected by CVE-2015-3225?
CVE-2015-3225 affects Rack versions before 1.5.4 and 1.6.x before 1.6.2, commonly used with Ruby on Rails 3.x and 4.x.
4
What type of attack does CVE-2015-3225 enable?
CVE-2015-3225 enables remote attackers to trigger a SystemStackError by sending requests with a large parameter depth.
5
Is CVE-2015-3225 a local or remote vulnerability?
CVE-2015-3225 is a remote vulnerability, allowing attackers to exploit it over a network.