REDHAT-BUG-895282: Medium severity rack vulnerability
Upstream released [1] Rack 1.4.3 and 1.3.8 to fix a denial of service condition due to a malicious client sending excessively long lines that trigger an out-of-memory error in Rack.
This has been fixed in git [2].
[1] https://groups.google.com/forum/#!topic/rack-devel/-MWPHDeGWtI/discussion [2] https://github.com/rack/rack/commit/f95113402b7239f225282806673e1b6424522b18
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-895282?
The severity of REDHAT-BUG-895282 is classified as a denial of service due to an out-of-memory error in Rack.
How do I fix REDHAT-BUG-895282?
To fix REDHAT-BUG-895282, upgrade your Rack version to at least 1.4.3 or 1.3.8.
What versions are affected by REDHAT-BUG-895282?
Rack versions between 1.3.8 and 1.4.2 are affected by REDHAT-BUG-895282.
What vulnerabilities does REDHAT-BUG-895282 address?
REDHAT-BUG-895282 addresses a denial of service vulnerability caused by excessively long lines sent by malicious clients.
Is there any workaround for REDHAT-BUG-895282?
There is no recommended workaround for REDHAT-BUG-895282 other than upgrading to a secure version.