CVE-2013-0183
Rack 1.3.0-1.3.7 and 1.4.0-1.4.2 - Denial of Service via Long String in Multipart HTTP Packet
Title source: llmDescription
multipart/parser.rb in Rack 1.3.x before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to cause a denial of service (memory consumption and out-of-memory error) via a long string in a Multipart HTTP packet.
References (10)
Core 10
Core References
Mailing List x_refsource_confirm
https://groups.google.com/forum/#%21topic/rack-devel/7ZKPNAjgRSs
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0548.html
Vendor Advisory vendor-advisory
x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2013-0544.html
Patch x_refsource_confirm
https://github.com/rack/rack/commit/548b9af2dc0059f4c0c19728624448d84de450ff
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=895282
Various Sources x_refsource_confirm
http://rack.github.com/
Mailing List x_refsource_confirm
https://groups.google.com/forum/#%21topic/rack-devel/-MWPHDeGWtI
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-updates/2013-03/msg00048.html
Patch x_refsource_confirm
https://github.com/rack/rack/commit/f95113402b7239f225282806673e1b6424522b18
Third Party Advisory vendor-advisory
x_refsource_debian
http://www.debian.org/security/2013/dsa-2783
Scores
EPSS
0.0182
EPSS Percentile
83.1%
Details
CWE
CWE-119
Status
published
Products (12)
rack_project/rack
1.3.0
rack_project/rack
1.3.1
rack_project/rack
1.3.2
rack_project/rack
1.3.3
rack_project/rack
1.3.4
rack_project/rack
1.3.5
rack_project/rack
1.3.6
rack_project/rack
1.3.7
rack_project/rack
1.4.0
rack_project/rack
1.4.1
... and 2 more
Published
Mar 01, 2013
Tracked Since
Feb 18, 2026