USN-7057-2: WEBrick vulnerability
USN-7057-1 fixed a vulnerability in WEBrick. This update provides the corresponding updates for Ubuntu 22.04 LTS. Original advisory details: It was discovered that WEBrick incorrectly handled having both a Content- Length header and a Transfer-Encoding header. A remote attacker could possibly use this issue to perform a HTTP request smuggling attack.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7057-2?
The severity of USN-7057-2 is categorized as a moderate vulnerability affecting WEBrick handling of headers.
How do I fix USN-7057-2?
To fix USN-7057-2, update the ruby-webrick package to version 1.7.0-3ubuntu0.1 or later on Ubuntu 22.04 LTS.
What software is affected by USN-7057-2?
USN-7057-2 affects the ruby-webrick package on Ubuntu 22.04 LTS.
What vulnerability does USN-7057-2 address?
USN-7057-2 addresses a vulnerability where WEBrick incorrectly handled both a Content-Length header and a Transfer-Encoding header.
Is USN-7057-2 applicable to Ubuntu versions other than 22.04?
No, USN-7057-2 specifically applies to Ubuntu 22.04 LTS.