USN-6399-1: Puma vulnerability
Published Sep 27, 2023
·Updated
It was discovered that Puma incorrectly handled parsing certain headers. A remote attacker could possibly use this issue to perform an HTTP request Smuggling attack.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/puma<5.6.5-3ubuntu1.1
5.6.5-3ubuntu1.1
Ubuntu Ubuntu=23.04
Event History
Sep 27, 2023
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Puma vulnerability?
The vulnerability ID for this Puma vulnerability is CVE-2023-40175.
2
How does the Puma vulnerability impact systems?
The Puma vulnerability can allow a remote attacker to perform an HTTP request smuggling attack.
3
What software is affected by this Puma vulnerability?
The Ubuntu 23.04 operating system with Puma version 5.6.5-3ubuntu1.1 is affected by this vulnerability.
4
How can I fix the Puma vulnerability?
To fix the Puma vulnerability, update the Puma package to version 5.6.5-3ubuntu1.1.
5
Where can I find more information about this Puma vulnerability?
More information about this Puma vulnerability can be found on the Ubuntu security notices website.