CVE-2015-3225
Published: 26 July 2015
lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a request with a large parameter depth.
From the Ubuntu Security Team
It was discovered that Rack incorrectly handled certain inputs. A remote attacker could possibly use this issue to cause a denial of service.
Priority
Status
Package | Release | Status |
---|---|---|
librack-ruby Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
|
|
upstream |
Needs triage
|
|
utopic |
Does not exist
|
|
vivid |
Does not exist
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|
|
ruby-rack Launchpad, Ubuntu, Debian |
artful |
Ignored
(reached end-of-life)
|
bionic |
Not vulnerable
(1.6.4-3)
|
|
cosmic |
Not vulnerable
(1.6.4-3)
|
|
disco |
Not vulnerable
(1.6.4-3)
|
|
eoan |
Not vulnerable
(1.6.4-3)
|
|
focal |
Not vulnerable
(1.6.4-3)
|
|
groovy |
Not vulnerable
(1.6.4-3)
|
|
hirsute |
Not vulnerable
(1.6.4-3)
|
|
impish |
Not vulnerable
(1.6.4-3)
|
|
jammy |
Not vulnerable
(1.6.4-3)
|
|
precise |
Does not exist
(precise was needed)
|
|
trusty |
Released
(1.5.2-1ubuntu0.1~esm1)
|
|
upstream |
Released
(1.5.2-3+deb8u1)
|
|
utopic |
Ignored
(reached end-of-life)
|
|
vivid |
Released
(1.5.2-3+deb8u1build0.15.04.1)
|
|
wily |
Ignored
(reached end-of-life)
|
|
xenial |
Not vulnerable
(1.6.4-3)
|
|
yakkety |
Ignored
(reached end-of-life)
|
|
zesty |
Ignored
(reached end-of-life)
|
|
ruby-rack1.4 Launchpad, Ubuntu, Debian |
artful |
Does not exist
|
bionic |
Does not exist
|
|
cosmic |
Does not exist
|
|
disco |
Does not exist
|
|
eoan |
Does not exist
|
|
focal |
Does not exist
|
|
groovy |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Does not exist
|
|
precise |
Does not exist
|
|
trusty |
Does not exist
(trusty was needed)
|
|
upstream |
Needed
(released ruby-rack 1.4.1-2.1+den7u1)
|
|
utopic |
Ignored
(reached end-of-life)
|
|
vivid |
Ignored
(reached end-of-life)
|
|
wily |
Does not exist
|
|
xenial |
Does not exist
|
|
yakkety |
Does not exist
|
|
zesty |
Does not exist
|