Date: Mon, 14 Jan 2013 17:20:15 -0700 From: Vincent Danen <vdanen@...hat.com> To: oss-security@...ts.openwall.com Subject: CVE request: 3 DoS conditions in Rake Three issues were noted in recent release of upstream Rake. All are DoS issues. From https://bugzilla.redhat.com/show_bug.cgi?id=895277 (2 issues): Upstream released  Rack 1.4.2, 1.3.7, 1.2.6, and 1.1.4 to fix a denial of service condition when Rack parses content with a certain Content-Disposition header as noted in the original report . This has been fixed in git . Additionally, a second flaw that was fixed in 1.4.4, 1.3.9, 1.2.7, and 1.1.5 was also announced  that creates a minor denial of service condition, this time in the Rack::Auth::AbstractRequest, where it symbolized arbitrary strings (apparently this has something to do with authentication, but there is no further information provided other than the fix  itself, which is noted as "a breaking API change").  http://rack.github.com/  https://groups.google.com/forum/#!msg/rack-devel/1w4_fWEgTdI/XAkSNHjtdTsJ  https://github.com/rack/rack/commit/4fc44671b3cad569421f4f8b775c0590b86f575e  https://groups.google.com/forum/#!topic/rack-devel/ImYOqcGiksw/discussion  https://github.com/rack/rack/commit/0c76175fcccad74ba2f991c487d3669c28a297c8 And from https://bugzilla.redhat.com/show_bug.cgi?id=895282: Upstream released  Rack 1.4.3 and 1.3.8 to fix a denial of service condition due to a malicious client sending excessively long lines that trigger an out-of-memory error in Rack. This has been fixed in git .  https://groups.google.com/forum/#!topic/rack-devel/-MWPHDeGWtI/discussion  https://github.com/rack/rack/commit/f95113402b7239f225282806673e1b6424522b18 Could three CVEs be assigned for these issues please? Thanks. -- Vincent Danen / Red Hat Security Response Team
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.