VDB
RHSA-2013%3A0548
RHSA-2013%3A0548
PUBLISHED
CVSS 4.300000190734863 MEDIUM
lib/rack/multipart.rb in Rack before 1.1.4, 1.2.x before 1.2.6, 1.3.x before 1.3.7, and 1.4.x before 1.4.2 uses an incorrect regular expression, which allows remote attackers to cause a denial of service (infinite loop) via a crafted Content-Disposion header.
Risk Scores
CVSS 2.0
4.300000190734863
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rubygem-rdoc-0:3.8-6.el6cf.noarch as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-rdoc-0:3.8-6.el6cf.noarch |
| Red Hat | rubygem-delayed_job-0:2.1.4-3.el6cf.src as a component of CloudForms System Engine for RHEL 6 Server | * |
| Red Hat | rubygem-rdoc-0:3.8-6.el6cf.src as a component of CloudForms System Engine for RHEL 6 Server | rubygem-rdoc-0:3.8-6.el6cf.src |
| Red Hat | rubygem-delayed_job-0:2.1.4-3.el6cf.noarch as a component of CloudForms System Engine for RHEL 6 Server | * |
| Red Hat | rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf.x86_64 as a component of CloudForms System Engine for RHEL 6 Server | rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf.x86_64 |
| Red Hat | rubygem-rspec-rails-0:2.6.1-7.el6cf.src as a component of CloudForms Cloud Engine for RHEL 6 Server | * |
| Red Hat | rubygem-rdoc-doc-0:3.8-6.el6cf.noarch as a component of CloudForms System Engine for RHEL 6 Server | * |
| Red Hat | rubygem-nokogiri-doc-0:1.5.0-0.9.beta4.el6cf.noarch as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-nokogiri-doc-0:1.5.0-0.9.beta4.el6cf.noarch |
| Red Hat | rubygem-activesupport-1:3.0.10-10.el6cf.src as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-activesupport-1:3.0.10-10.el6cf.src |
| Red Hat | rubygem-rack-1:1.3.0-3.el6cf.src as a component of CloudForms System Engine for RHEL 6 Server | rubygem-rack-1:1.3.0-3.el6cf.src |
| Red Hat | rubygem-shoulda-doc-0:2.11.3-5.el6cf.noarch as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-shoulda-doc-0:2.11.3-5.el6cf.noarch |
| Red Hat | rubygem-delayed_job-0:2.1.4-3.el6cf.noarch as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-delayed_job-0:2.1.4-3.el6cf.noarch |
| Red Hat | rubygem-shoulda-0:2.11.3-5.el6cf.src as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-shoulda-0:2.11.3-5.el6cf.src |
| Red Hat | rubygem-nokogiri-debuginfo-0:1.5.0-0.9.beta4.el6cf.x86_64 as a component of CloudForms System Engine for RHEL 6 Server | rubygem-nokogiri-debuginfo-0:1.5.0-0.9.beta4.el6cf.x86_64 |
| Red Hat | rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf.x86_64 as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-nokogiri-0:1.5.0-0.9.beta4.el6cf.x86_64 |
| Red Hat | rubygem-ruby_parser-0:2.0.4-6.el6cf.src as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-ruby_parser-0:2.0.4-6.el6cf.src |
| Red Hat | rubygem-rdoc-doc-0:3.8-6.el6cf.noarch as a component of CloudForms Cloud Engine for RHEL 6 Server | * |
| Red Hat | rubygem-rails_warden-0:0.5.5-2.el6cf.noarch as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-rails_warden-0:0.5.5-2.el6cf.noarch |
| Red Hat | rubygem-delayed_job-0:2.1.4-3.el6cf.src as a component of CloudForms Cloud Engine for RHEL 6 Server | rubygem-delayed_job-0:2.1.4-3.el6cf.src |
| Red Hat | rubygem-rdoc-0:3.8-6.el6cf.noarch as a component of CloudForms System Engine for RHEL 6 Server | rubygem-rdoc-0:3.8-6.el6cf.noarch |
…and 28 more
Timeline
- Feb 21, 2013 CVE Published
- Mar 27, 2026 CVE Updated
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Distribution Patch
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
- Apr 29, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHSA-2013:0548 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/knowledge/docs/ advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=892806 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=895277 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=895282 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=895384 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=907820 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2013/rhsa-2013_0548.json advisory
- https://access.redhat.com/security/cve/CVE-2012-6109 advisory
- https://www.cve.org/CVERecord?id=CVE-2012-6109 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-6109 advisory
- https://access.redhat.com/security/cve/CVE-2013-0162 advisory
- https://www.cve.org/CVERecord?id=CVE-2013-0162 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-0162 advisory
- https://access.redhat.com/security/cve/CVE-2013-0183 advisory
- https://www.cve.org/CVERecord?id=CVE-2013-0183 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2013-0183 advisory
- https://access.redhat.com/security/cve/CVE-2013-0184 advisory
- https://www.cve.org/CVERecord?id=CVE-2013-0184 advisory
…and 5 more