REDHAT-BUG-909071: Medium severity rack vulnerability
James Tucker (raggi) reports:
CVE: CVE-2013-0263 Software: Rack (rack.github.com) Type of vulnerability: Timing attack, leading to potential RCE
Vulnerable code: https://github.com/rack/rack/blob/master/lib/rack/session/cookie.rb#L149 Patch: https://github.com/rack/rack/commit/0cd7e9aa397f8ebb3b8481d67dbac8b4863a7f07 https://github.com/rack/rack/commit/9a81b961457805f6d1a5c275d053068440421e11
Versions affected: All prior versions. Versions fixed: 1.1.6, 1.2.8, 1.3.10, 1.4.5, 1.5.2 Reporter: Ben Murphy
Reference: http://seclists.org/oss-sec/2013/q1/271
Affected Software
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-909071?
The severity of REDHAT-BUG-909071 is considered high due to its potential for remote code execution through a timing attack.
How do I fix REDHAT-BUG-909071?
To fix REDHAT-BUG-909071, it is recommended to upgrade Rack to version 1.6.0 or later.
Which versions of Rack are affected by REDHAT-BUG-909071?
Versions of Rack prior to 1.6.0, specifically 1.1.6 through 1.5.2, are affected by REDHAT-BUG-909071.
What type of vulnerability is indicated by REDHAT-BUG-909071?
REDHAT-BUG-909071 is classified as a timing attack vulnerability.
What can potentially be compromised due to REDHAT-BUG-909071?
REDHAT-BUG-909071 could potentially lead to unauthorized remote code execution.